OTL logfile created on: 1/1/2012 11:28:19 AM - Run 1 OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Jill\Desktop Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 3.00 Gb Total Physical Memory | 2.11 Gb Available Physical Memory | 70.27% Memory free 4.84 Gb Paging File | 3.53 Gb Available in Paging File | 72.99% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 144.80 Gb Total Space | 36.34 Gb Free Space | 25.09% Space Free | Partition Type: NTFS Drive I: | 968.25 Mb Total Space | 966.23 Mb Free Space | 99.79% Space Free | Partition Type: FAT Drive M: | 1863.01 Gb Total Space | 1332.22 Gb Free Space | 71.51% Space Free | Partition Type: NTFS Computer Name: DBP3RKB1 | User Name: Jill | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days [color=#E56717]========== Processes (SafeList) ==========[/color] PRC - [2012/01/01 11:26:45 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jill\Desktop\OTL.exe PRC - [2011/12/12 23:20:56 | 003,305,760 | ---- | M] (Akamai Technologies, Inc) -- C:\Documents and Settings\Jill\Local Settings\Application Data\Akamai\netsession_win.exe PRC - [2011/12/05 14:17:44 | 024,242,056 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\Jill\Application Data\Dropbox\bin\Dropbox.exe PRC - [2011/11/28 13:01:24 | 003,744,552 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe PRC - [2011/11/28 13:01:23 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe PRC - [2011/11/17 20:27:30 | 006,860,960 | ---- | M] (Spotify Ltd) -- C:\Documents and Settings\Kramer\Application Data\Spotify\spotify.exe PRC - [2011/07/19 20:48:30 | 006,346,040 | ---- | M] (Radialpoint SafeCare Inc.) -- C:\Program Files\Windstream\Service Agent\Windstream Service AgentComHandler.exe PRC - [2011/07/19 20:48:24 | 010,302,776 | ---- | M] (Radialpoint SafeCare Inc.) -- C:\Program Files\Windstream\Service Agent\ServicepointService.exe PRC - [2011/07/19 20:48:24 | 010,196,280 | ---- | M] (Windstream) -- C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe PRC - [2011/04/30 19:19:55 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe PRC - [2011/04/25 14:34:34 | 001,393,976 | ---- | M] (Windstream) -- C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe PRC - [2011/04/25 14:34:32 | 002,037,048 | ---- | M] (Windstream) -- C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe PRC - [2011/04/22 07:21:10 | 000,247,728 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe PRC - [2011/04/22 07:21:10 | 000,092,592 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe PRC - [2011/04/01 00:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe PRC - [2010/05/07 17:35:22 | 000,165,208 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe PRC - [2010/01/16 12:02:38 | 000,436,752 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\mcuicnt.exe PRC - [2010/01/15 07:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe PRC - [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe PRC - [2007/11/13 16:46:00 | 000,135,168 | ---- | M] ( ) -- C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe PRC - [2007/07/20 14:21:34 | 000,557,056 | ---- | M] (Lavasoft AB) -- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe PRC - [2007/03/15 10:09:36 | 000,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe PRC - [2007/01/31 14:55:42 | 000,096,370 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe PRC - [2007/01/04 16:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe PRC - [2006/05/03 03:12:00 | 000,098,304 | ---- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe PRC - [2006/03/02 03:00:18 | 000,018,944 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\CTXFIHLP.EXE PRC - [2006/03/02 02:53:36 | 000,717,312 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\CTXFISPI.EXE PRC - [2005/11/08 11:30:42 | 000,016,384 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\CTHELPER.EXE PRC - [2005/09/08 04:20:00 | 000,122,940 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLACTRLW.EXE PRC - [2004/08/04 04:00:00 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rsmsink.exe PRC - [2004/04/07 11:07:32 | 001,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe [color=#E56717]========== Modules (No Company Name) ==========[/color] MOD - [2012/01/01 04:19:50 | 001,660,928 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12010100\algo.dll MOD - [2011/12/31 13:36:36 | 001,660,928 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\11123101\algo.dll MOD - [2011/12/31 10:01:54 | 000,268,808 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12010100\aswRep.dll MOD - [2011/12/31 10:01:54 | 000,268,808 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\11123101\aswRep.dll MOD - [2011/12/14 15:20:17 | 003,316,000 | ---- | M] () -- c:\Program Files\Common Files\Akamai\netsession_win_b427739.dll MOD - [2011/09/27 06:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2011/09/27 06:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2009/08/05 09:45:04 | 000,106,312 | ---- | M] () -- C:\Program Files\Microsoft Office\OFFICE11\OUTLCTL.DLL MOD - [2009/06/10 20:08:45 | 000,140,800 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll MOD - [2007/06/07 19:27:50 | 000,520,192 | ---- | M] () -- C:\Program Files\Lavasoft\Ad-Aware 2007\Update.dll MOD - [2005/11/08 20:30:00 | 000,003,072 | ---- | M] () -- C:\WINDOWS\CTXFIRES.DLL MOD - [2004/08/04 04:00:00 | 000,015,360 | ---- | M] () -- C:\WINDOWS\system32\tsd32.dll [color=#E56717]========== Win32 Services (SafeList) ==========[/color] SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt) SRV - [2011/12/14 15:20:17 | 003,316,000 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_b427739.dll -- (Akamai) SRV - [2011/11/28 13:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus) SRV - [2011/07/19 20:48:24 | 010,302,776 | ---- | M] (Radialpoint SafeCare Inc.) [Auto | Running] -- C:\Program Files\Windstream\Service Agent\ServicepointService.exe -- (ServicepointService) SRV - [2011/04/25 14:34:34 | 001,393,976 | ---- | M] (Windstream) [Auto | Running] -- C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe -- (HsdService) SRV - [2011/04/22 07:21:10 | 000,092,592 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService) SRV - [2011/04/01 00:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv) SRV - [2010/01/15 07:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService) SRV - [2008/10/20 18:27:30 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2007/07/20 14:21:34 | 000,557,056 | ---- | M] (Lavasoft AB) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe -- (aawservice) SRV - [2007/03/07 14:47:46 | 000,076,848 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService) SRV - [2007/01/31 14:55:42 | 000,096,370 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8) SRV - [2007/01/04 16:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Auto | Running] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service) SRV - [2004/04/07 11:07:32 | 001,135,728 | ---- | M] (America Online, Inc.) [Auto | Running] -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe -- (AOL ACS) [color=#E56717]========== Driver Services (SafeList) ==========[/color] DRV - [2011/11/28 12:53:53 | 000,435,032 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx) DRV - [2011/11/28 12:53:35 | 000,314,456 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP) DRV - [2011/11/28 12:52:19 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr) DRV - [2011/11/28 12:52:16 | 000,052,952 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi) DRV - [2011/11/28 12:52:02 | 000,111,320 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2) DRV - [2011/11/28 12:51:50 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk) DRV - [2011/11/28 12:48:49 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4) DRV - [2011/04/01 00:11:10 | 004,333,280 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC) Logitech HD Webcam C525(UVC) DRV - [2011/04/01 00:09:48 | 000,291,424 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvrs.sys -- (LVRS) DRV - [2011/04/01 00:07:52 | 000,020,448 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvbusflt.sys -- (CompFilter) DRV - [2010/04/30 19:32:06 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50) DRV - [2010/04/30 19:30:56 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50) DRV - [2009/07/13 15:51:12 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\winusb.sys -- (WinUSB) DRV - [2008/04/13 14:46:22 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MPE.sys -- (MPE) DRV - [2008/04/13 13:56:49 | 000,012,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usb8023.sys -- (USB_RNDIS) DRV - [2007/02/25 11:10:48 | 000,005,376 | --S- | M] (Gteko Ltd.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\dsunidrv.sys -- (dsunidrv) DRV - [2006/12/12 11:16:06 | 000,022,528 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\emAudio.sys -- (emAudio) DRV - [2006/10/05 15:07:28 | 000,004,736 | ---- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct) DRV - [2006/02/15 05:40:24 | 001,096,192 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ha20x2k.sys -- (ha20x2k) DRV - [2006/02/09 20:57:46 | 001,502,208 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag) DRV - [2005/12/21 09:14:52 | 000,100,957 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\emDevice.sys -- (DCamUSBEMPIA) DRV - [2005/12/21 09:14:52 | 000,005,245 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\emFilter.sys -- (FiltUSBEMPIA) DRV - [2005/12/21 09:14:52 | 000,004,493 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\emScan.sys -- (ScanUSBEMPIA) DRV - [2005/11/08 11:15:38 | 000,439,680 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM) DRV - [2005/11/08 11:15:38 | 000,007,168 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctprxy2k.sys -- (ctprxy2k) DRV - [2005/11/08 11:14:44 | 000,077,824 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\emupia2k.sys -- (emupia) DRV - [2005/11/08 11:14:40 | 000,502,272 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctac32k.sys -- (ctac32k) DRV - [2005/11/08 07:14:54 | 000,114,688 | R--- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv) DRV - [2005/11/08 07:14:46 | 000,143,360 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ctsfm2k.sys -- (ctsfm2k) DRV - [2005/09/08 04:20:00 | 000,094,332 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM) DRV - [2005/09/08 04:20:00 | 000,087,036 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M) DRV - [2005/09/08 04:20:00 | 000,086,524 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M) DRV - [2005/09/08 04:20:00 | 000,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM) DRV - [2005/09/08 04:20:00 | 000,014,684 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM) DRV - [2005/09/08 04:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM) DRV - [2005/09/08 04:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN) DRV - [2005/08/25 11:16:52 | 000,005,628 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM) DRV - [2005/08/25 11:16:16 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N) DRV - [2005/07/13 04:18:48 | 000,340,704 | R--- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ctdvda2k.sys -- (ctdvda2k) DRV - [2003/11/17 20:59:20 | 000,212,224 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2) DRV - [2003/11/17 20:58:02 | 000,680,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf) DRV - [2003/11/17 20:56:26 | 001,042,432 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP) DRV - [2003/09/25 21:15:32 | 000,015,872 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\GTNDIS5.sys -- (GTNDIS5) DRV - [2003/01/10 15:13:04 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW) [color=#E56717]========== Standard Registry (SafeList) ==========[/color] [color=#E56717]========== Internet Explorer ==========[/color] IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.windstream.net/ IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.espn.com/ IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - No CLSID value found IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://myspace.com/ IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local [color=#E56717]========== FireFox ==========[/color] FF - prefs.js..browser.search.defaulturl: "http://aim.search.aol.com/search/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://www.marykayintouch.com/" FF - prefs.js..extensions.enabledItems: {c2f863cd-0429-48c7-bb54-db756a951760}:5.96.10.6044 FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.60 FF - prefs.js..extensions.enabledItems: [removed]:4.60 FF - prefs.js..extensions.enabledItems: [removed]:1.0 FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.3.5.20110120033202 FF - prefs.js..browser.search.defaultenginename: "Yahoo" FF - prefs.js..browser.search.selectedEngine: "Yahoo" FF - prefs.js..keyword.URL: "http://search.yahoo.com/search?ei=utf-8&fr=greentree_ff1&type=937811&ilc=12&p=" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=937811&ilc=12" FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.) FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files\Common Files\Motive\npMotive.dll (Alcatel-Lucent) FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files\Windstream\Service Agent\nprpspa.dll (Windstream) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.46: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.46: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll () FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Documents and Settings\Jill\Application Data\Facebook\npfbplugin_1_0_3.dll ( ) FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Program Files\Real\RealPlayer\browserrecord [2008/05/20 05:16:26 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/22 17:20:08 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/12/27 11:43:29 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.5\extensions\\Components: C:\Program Files\Flock\components [2011/09/16 16:13:50 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.5\extensions\\Plugins: C:\Program Files\Flock\plugins [2011/11/14 19:33:39 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/12/22 19:53:11 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.5.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/12/10 23:56:18 | 000,000,000 | ---D | M] FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/22 17:20:08 | 000,000,000 | ---D | M] [2010/06/27 19:05:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jill\Application Data\Mozilla\Extensions [2010/06/27 19:05:31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jill\Application Data\Mozilla\Extensions\[removed] [2011/09/02 04:51:20 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Jill\Application Data\Mozilla\Firefox\Profiles\f1a7voaw.default\extensions [2010/08/15 19:25:40 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Jill\Application Data\Mozilla\Firefox\Profiles\f1a7voaw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2011/08/08 12:33:12 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Jill\Application Data\Mozilla\Firefox\Profiles\f1a7voaw.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2010/08/15 19:26:01 | 000,000,000 | ---D | M] (AIM Toolbar) -- C:\Documents and Settings\Jill\Application Data\Mozilla\Firefox\Profiles\f1a7voaw.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760} [2010/01/09 09:11:39 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus(R))) -- C:\Documents and Settings\Jill\Application Data\Mozilla\Firefox\Profiles\f1a7voaw.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7} [2009/10/15 05:50:27 | 000,004,546 | ---- | M] () -- C:\Documents and Settings\Jill\Application Data\Mozilla\Firefox\Profiles\f1a7voaw.default\searchplugins\aim-search-1.xml [2010/08/15 18:29:58 | 000,004,554 | ---- | M] () -- C:\Documents and Settings\Jill\Application Data\Mozilla\Firefox\Profiles\f1a7voaw.default\searchplugins\aim-search-2.xml [2008/11/16 22:43:33 | 000,001,739 | ---- | M] () -- C:\Documents and Settings\Jill\Application Data\Mozilla\Firefox\Profiles\f1a7voaw.default\searchplugins\aim-search.xml [2011/12/27 16:36:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2011/03/28 05:04:22 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2010/01/22 17:20:08 | 000,000,000 | ---D | M] (HP Smart Web Printing) -- C:\PROGRAM FILES\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON3 [2008/12/30 14:11:56 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/08/12 16:52:01 | 000,036,864 | ---- | M] (Homestead Technologies, Inc.) -- C:\Program Files\mozilla firefox\plugins\nphssb.dll [2007/03/05 13:59:06 | 000,645,504 | ---- | M] (Microsoft Corporation) -- C:\Program Files\mozilla firefox\plugins\npOGAPlugin.dll [2008/09/15 11:52:06 | 000,376,832 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npsnapfish.dll [2007/07/18 11:19:40 | 002,998,784 | ---- | M] (Tamarack Software, Inc.) -- C:\Program Files\mozilla firefox\plugins\nptgeqplugin.dll [2007/04/16 12:07:12 | 000,180,293 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npViewpoint.dll O1 HOSTS File: ([2007/09/22 17:18:00 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated) O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions) O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found. O3 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008\..\Toolbar\WebBrowser: (no name) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - No CLSID value found. O3 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found. O3 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009\..\Toolbar\WebBrowser: (no name) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - No CLSID value found. O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll" File not found O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software) O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\CTHELPER.EXE (Creative Technology Ltd) O4 - HKLM..\Run: [CTxfiHlp] C:\WINDOWS\System32\CTXFIHLP.EXE (Creative Technology Ltd) O4 - HKLM..\Run: [DiagnosticTools.exe] C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe (Windstream) O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions) O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe () O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.) O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" File not found O4 - HKLM..\Run: [USB2Check] C:\WINDOWS\System32\PCLECoInst.dll (Pinnacle Systems) O4 - HKLM..\Run: [Windstream Service Agent.exe] C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe (Windstream) O4 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007..\Run: [Akamai NetSession Interface] C:\Documents and Settings\Jill\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc) O4 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.) O4 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe" File not found O4 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom) O4 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.) O4 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008..\Run: [DellTransferAgent] C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe ( ) O4 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" File not found O4 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp File not found O4 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.) O4 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009..\Run: [DellTransferAgent] C:\Documents and Settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe ( ) O4 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background File not found O4 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" File not found O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation) O4 - HKU\.DEFAULT..\RunOnce: [SetDefaultMIDI] C:\WINDOWS\MIDIDEF.EXE (Creative Technology Ltd) O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation) O4 - HKU\S-1-5-18..\RunOnce: [SetDefaultMIDI] C:\WINDOWS\MIDIDEF.EXE (Creative Technology Ltd) O4 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10x_ActiveX.exe (Adobe Systems, Inc.) O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk = C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.) O4 - Startup: C:\Documents and Settings\Jill\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Jill\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1008\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-2085009153-3855714761-1712164351-1009\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} http://www.support.dell.com/systemprofiler/SysPro.CAB (SysProWmi Class) O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control) O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool) O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool) O16 - DPF: {1A1F56AA-3401-46F9-B277-D57F3421F821} http://gsn.worldwinner.com/games/v47/shared/FunGamesLoader.cab (FunGamesLoader Object) O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} http://www.worldwinner.com/games/v50/tpir/tpir.cab (TPIR Control) O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} http://a516.g.akamai.net/f/516/25175/7d/runaware.download.akamai.com/25175/citrix/wficat-no-eula.cab (Citrix ICA Client) O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine) O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab (DLM Control) O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control) O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab (Reg Error: Key error.) O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} http://upload.facebook.com/controls/FacebookPhotoUploader3.cab (Facebook Photo Uploader 4 Control) O16 - DPF: {61900274-3323-4446-BDCD-91548D32AF1B} http://www.worldwinner.com/games/v56/spidersolitaire/spidersolitaire.cab (SpiderSolitaire Control) O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinner.com/games/shared/wwlaunch.cab (Wwlaunch Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} http://lads.myspace.com/upload/MySpaceUploader2.cab (MySpace Uploader Control) O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine) O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab (Java Plug-in 1.6.0_17) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/webgames/popcaploader_v10.cab (PopCapLoader Object) O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254 192.168.254.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{23619039-C929-4F3E-95B5-9D4EDE332247}: DhcpNameServer = 192.168.254.254 192.168.254.254 O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Documents and Settings\Jill\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jill\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2004/08/10 12:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O32 - AutoRun File - [2010/05/07 03:01:54 | 000,000,162 | ---- | M] () - M:\Autorun.inf -- [ NTFS ] O33 - MountPoints2\{e38facac-87b0-11de-a3ad-0018390f7544}\Shell - "" = AutoRun O33 - MountPoints2\{e38facac-87b0-11de-a3ad-0018390f7544}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{e38facac-87b0-11de-a3ad-0018390f7544}\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (lsdelete) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* [color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color] [2012/01/01 11:26:39 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Jill\Desktop\OTL.exe [2011/12/31 22:16:12 | 002,031,992 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Jill\Desktop\MGADiag.exe [2011/12/31 22:05:29 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\Jill\Desktop\dds.com [2011/12/28 14:36:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jill\Desktop\Mrs. Gail [2011/12/28 08:31:03 | 000,000,000 | ---D | C] -- C:\spoolerlogs [2011/12/27 11:43:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus [2011/12/27 11:43:45 | 000,314,456 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys [2011/12/27 11:43:45 | 000,020,568 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys [2011/12/27 11:43:43 | 000,052,952 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys [2011/12/27 11:43:43 | 000,034,392 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys [2011/12/27 11:43:42 | 000,435,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys [2011/12/27 11:43:42 | 000,111,320 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys [2011/12/27 11:43:42 | 000,105,176 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys [2011/12/27 11:43:41 | 000,030,808 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys [2011/12/27 11:43:27 | 000,041,184 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr [2011/12/27 11:43:26 | 000,199,816 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe [2011/12/27 11:43:14 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software [2011/12/27 10:27:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jill\Start Menu\Programs\HiJackThis [2011/12/27 10:27:48 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro [2011/12/17 22:24:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jill\Desktop\A Christmas Celebration 2011 [2011/12/17 07:00:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jill\Desktop\Purity Ceremony pics 2011 [2011/12/17 06:56:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jill\Desktop\Women's Christmas Party 2011 [2011/12/10 23:31:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Jill\Desktop\HHR Christmas Outreach 2011 [2011/12/10 09:11:14 | 000,205,072 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys [2006/12/12 09:47:24 | 000,033,792 | R--- | C] ( ) -- C:\WINDOWS\System32\a3d.dll [2006/08/02 12:57:56 | 000,009,216 | ---- | C] ( ) -- C:\WINDOWS\System32\KILLAPPS.EXE [8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [2 C:\Documents and Settings\Jill\My Documents\*.tmp files -> C:\Documents and Settings\Jill\My Documents\*.tmp -> ] [1 C:\Documents and Settings\Jill\Desktop\*.tmp files -> C:\Documents and Settings\Jill\Desktop\*.tmp -> ] [color=#E56717]========== Files - Modified Within 30 Days ==========[/color] [2012/01/01 11:26:45 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Jill\Desktop\OTL.exe [2012/01/01 10:54:02 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2011/12/31 22:42:55 | 000,002,521 | ---- | M] () -- C:\Documents and Settings\Jill\Desktop\Microsoft Office Outlook 2003.lnk [2011/12/31 22:24:40 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2011/12/31 22:16:25 | 002,031,992 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Jill\Desktop\MGADiag.exe [2011/12/31 22:11:04 | 000,879,683 | ---- | M] () -- C:\Documents and Settings\Jill\Desktop\SecurityCheck.exe [2011/12/31 22:05:34 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\Jill\Desktop\dds.com [2011/12/31 20:54:03 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2011/12/31 03:37:58 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{0B0DD807-2F52-4516-A18E-98AC2B9C46FB}.job [2011/12/29 23:39:00 | 000,000,262 | ---- | M] () -- C:\WINDOWS\tasks\Spybot - Search & Destroy.job [2011/12/29 14:48:58 | 000,002,497 | ---- | M] () -- C:\Documents and Settings\Jill\Desktop\Microsoft Office Word 2003.lnk [2011/12/29 12:37:45 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2011/12/29 12:37:42 | 3219,279,872 | -HS- | M] () -- C:\hiberfil.sys [2011/12/28 13:56:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job [2011/12/28 12:17:23 | 000,002,445 | ---- | M] () -- C:\Documents and Settings\Jill\Desktop\HiJackThis.lnk [2011/12/28 10:54:37 | 000,123,392 | ---- | M] () -- C:\Documents and Settings\Jill\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011/12/27 18:06:11 | 000,064,980 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000003-00000000-00000003-00001102-00000005-10031102}.rfx [2011/12/27 18:06:11 | 000,054,788 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000003-00000000-00000003-00001102-00000005-10031102}.rfx [2011/12/27 18:06:11 | 000,054,788 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000003-00000000-00000003-00001102-00000005-10031102}.rfx [2011/12/27 18:06:11 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm [2011/12/27 18:06:11 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm [2011/12/27 11:43:46 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk [2011/12/27 11:43:42 | 000,002,625 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT [2011/12/21 01:17:23 | 000,136,862 | ---- | M] () -- C:\Documents and Settings\Jill\Desktop\sisters 2010 _2011.jpg [2011/12/21 01:12:26 | 001,193,984 | ---- | M] () -- C:\Documents and Settings\Jill\Desktop\sisters.pub [2011/12/21 01:05:34 | 000,002,443 | ---- | M] () -- C:\Documents and Settings\Jill\Desktop\Microsoft Office Publisher 2003.lnk [2011/12/19 23:43:13 | 000,058,880 | ---- | M] () -- C:\Documents and Settings\Jill\My Documents\Jesse and Jennifer.pub [2011/12/18 22:16:10 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat [2011/12/17 22:33:51 | 001,093,771 | ---- | M] () -- C:\Documents and Settings\Jill\Desktop\sisters 2011.JPG [2011/12/15 05:37:38 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\Jill\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk [2011/12/15 05:37:33 | 000,463,720 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2011/12/15 05:37:33 | 000,080,848 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2011/12/15 03:29:11 | 000,325,912 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2011/12/15 03:11:36 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK [2011/12/11 09:43:11 | 007,406,127 | ---- | M] () -- C:\Documents and Settings\Jill\Desktop\FCC Events 12.10.11_0001.wmv [2011/12/10 09:11:12 | 000,205,072 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys [2011/12/10 08:51:07 | 000,000,983 | ---- | M] () -- C:\Documents and Settings\Jill\Start Menu\Programs\Startup\Dropbox.lnk [2011/12/10 08:51:07 | 000,000,983 | ---- | M] () -- C:\Documents and Settings\Jill\Desktop\Dropbox.lnk [2011/12/09 22:35:26 | 000,090,624 | ---- | M] () -- C:\Documents and Settings\Jill\Desktop\Christmas Events Flyer_web.pub [2011/12/09 22:24:10 | 000,090,624 | ---- | M] () -- C:\Documents and Settings\Jill\Desktop\Christmas Events Flyer.pub [2011/12/06 23:29:32 | 000,009,650 | ---- | M] () -- C:\Documents and Settings\Jill\Desktop\TSAL_wallpaper5_sm.jpg [8 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [2 C:\Documents and Settings\Jill\My Documents\*.tmp files -> C:\Documents and Settings\Jill\My Documents\*.tmp -> ] [1 C:\Documents and Settings\Jill\Desktop\*.tmp files -> C:\Documents and Settings\Jill\Desktop\*.tmp -> ] [color=#E56717]========== Files Created - No Company Name ==========[/color] [2011/12/31 22:11:01 | 000,879,683 | ---- | C] () -- C:\Documents and Settings\Jill\Desktop\SecurityCheck.exe [2011/12/28 16:06:56 | 000,000,424 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{0B0DD807-2F52-4516-A18E-98AC2B9C46FB}.job [2011/12/27 11:43:46 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk [2011/12/27 10:27:49 | 000,002,445 | ---- | C] () -- C:\Documents and Settings\Jill\Desktop\HiJackThis.lnk [2011/12/21 01:12:26 | 001,193,984 | ---- | C] () -- C:\Documents and Settings\Jill\Desktop\sisters.pub [2011/12/21 01:12:15 | 000,136,862 | ---- | C] () -- C:\Documents and Settings\Jill\Desktop\sisters 2010 _2011.jpg [2011/12/21 01:05:30 | 001,093,771 | ---- | C] () -- C:\Documents and Settings\Jill\Desktop\sisters 2011.JPG [2011/12/21 01:04:33 | 000,039,501 | ---- | C] () -- C:\Documents and Settings\Jill\Desktop\sisters 2010.JPG [2011/12/19 23:43:13 | 000,058,880 | ---- | C] () -- C:\Documents and Settings\Jill\My Documents\Jesse and Jennifer.pub [2011/12/11 09:42:07 | 007,406,127 | ---- | C] () -- C:\Documents and Settings\Jill\Desktop\FCC Events 12.10.11_0001.wmv [2011/12/09 22:35:26 | 000,090,624 | ---- | C] () -- C:\Documents and Settings\Jill\Desktop\Christmas Events Flyer_web.pub [2011/12/09 21:53:36 | 000,090,624 | ---- | C] () -- C:\Documents and Settings\Jill\Desktop\Christmas Events Flyer.pub [2011/12/06 23:29:54 | 000,009,650 | ---- | C] () -- C:\Documents and Settings\Jill\Desktop\TSAL_wallpaper5_sm.jpg [2011/07/24 13:02:20 | 000,313,207 | R--- | C] () -- C:\WINDOWS\System32\ctstatic.dat [2011/07/24 13:02:20 | 000,053,932 | R--- | C] () -- C:\WINDOWS\System32\ctdaught.dat [2011/07/24 13:02:19 | 000,366,255 | R--- | C] () -- C:\WINDOWS\System32\ctdlang.dat [2011/07/24 12:46:51 | 000,000,152 | ---- | C] () -- C:\WINDOWS\CoolPlay.ini [2011/07/24 09:15:31 | 000,000,347 | ---- | C] () -- C:\WINDOWS\CTWave32.INI [2011/07/24 09:06:24 | 000,000,029 | ---- | C] () -- C:\WINDOWS\sfbm.INI [2011/04/01 00:07:02 | 010,877,272 | ---- | C] () -- C:\WINDOWS\System32\LogiDPP.dll [2011/04/01 00:07:02 | 000,102,744 | ---- | C] () -- C:\WINDOWS\System32\LogiDPPApp.exe [2011/04/01 00:06:56 | 000,331,608 | ---- | C] () -- C:\WINDOWS\System32\DevManagerCore.dll [2011/03/31 23:56:00 | 000,027,872 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini [2011/03/28 05:05:09 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat [2011/03/22 22:58:22 | 000,014,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLFT2.dll [2010/12/07 19:17:11 | 000,000,062 | -H-- | C] () -- C:\WINDOWS\popcreg.dat [2010/12/07 19:17:11 | 000,000,034 | ---- | C] () -- C:\WINDOWS\popcinfot.dat [2010/04/20 20:17:42 | 000,019,517 | ---- | C] () -- C:\WINDOWS\hpqins13.dat [2010/03/02 20:31:24 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat [2010/01/22 17:18:45 | 000,023,109 | ---- | C] () -- C:\WINDOWS\hpqins15.dat [2009/12/26 16:12:28 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\PsisDecd.dll [2009/12/18 08:20:15 | 000,077,373 | ---- | C] () -- C:\WINDOWS\hpqins05.dat [2009/11/27 08:38:11 | 000,069,816 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat [2009/09/11 17:30:19 | 000,876,544 | ---- | C] () -- C:\WINDOWS\System32\TEACico2.dll [2009/08/12 16:52:29 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat [2009/08/12 16:51:32 | 000,098,136 | ---- | C] () -- C:\WINDOWS\gzip.exe [2009/04/04 07:12:25 | 000,166,432 | ---- | C] () -- C:\WINDOWS\hpoins29.dat [2009/04/04 07:12:25 | 000,000,799 | ---- | C] () -- C:\WINDOWS\hpomdl29.dat [2009/02/17 20:19:01 | 000,003,072 | ---- | C] () -- C:\WINDOWS\CTXFIRES.DLL [2009/02/17 20:11:14 | 000,520,192 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe [2008/07/06 13:53:20 | 000,000,049 | ---- | C] () -- C:\WINDOWS\lexstat.ini [2008/07/06 07:16:36 | 000,000,471 | ---- | C] () -- C:\WINDOWS\dellstat.ini [2008/04/04 20:30:37 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Gems [2008/04/04 20:30:37 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Jill\Application Data\Fruit [2008/04/04 20:30:37 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLds.DAT [2007/09/22 17:12:18 | 000,109,056 | ---- | C] () -- C:\WINDOWS\catchme.exe [2007/09/22 17:12:18 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\VFind.exe [2007/09/22 17:12:18 | 000,038,400 | ---- | C] () -- C:\WINDOWS\System32\moveex.exe [2007/07/23 17:13:34 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT [2007/07/05 17:20:55 | 000,000,022 | ---- | C] () -- C:\WINDOWS\kodakpcd.Jill.ini [2007/04/13 14:19:52 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe [2006/12/15 15:48:09 | 000,000,029 | ---- | C] () -- C:\WINDOWS\atid.ini [2006/12/12 09:34:04 | 000,005,120 | ---- | C] () -- C:\WINDOWS\System32\ENLOCSTR.EXE [2006/11/22 14:31:02 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache [2006/10/30 20:49:51 | 000,038,467 | ---- | C] () -- C:\Documents and Settings\Jill\Application Data\Comma Separated Values (Windows).ADR [2006/10/13 11:30:10 | 000,676,224 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.DLL [2006/10/13 07:16:51 | 000,004,961 | ---- | C] () -- C:\WINDOWS\mozver.dat [2006/09/30 11:36:38 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\Jill\Application Data\dvd.bmk [2006/09/25 21:26:36 | 000,003,766 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys [2006/09/25 21:26:36 | 000,000,088 | RHS- | C] () -- C:\WINDOWS\System32\F414507149.sys [2006/09/25 17:39:09 | 000,032,768 | ---- | C] () -- C:\WINDOWS\System32\instlsp.exe [2006/08/21 05:55:56 | 000,123,392 | ---- | C] () -- C:\Documents and Settings\Jill\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2006/08/13 10:01:30 | 000,000,026 | ---- | C] () -- C:\WINDOWS\popcinfo.dat [2006/08/10 20:27:44 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll [2006/08/07 17:35:33 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll [2006/08/06 22:48:16 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Jill\Local Settings\Application Data\fusioncache.dat [2006/08/02 13:43:42 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini [2006/08/02 13:33:20 | 000,000,275 | ---- | C] () -- C:\WINDOWS\wininit.ini [2006/08/02 13:29:49 | 000,149,504 | ---- | C] () -- C:\WINDOWS\UNWISE.EXE [2006/08/02 13:25:52 | 000,000,335 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2006/08/02 13:24:05 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI [2006/08/02 12:57:56 | 000,265,066 | ---- | C] () -- C:\WINDOWS\System32\CTSBAS2W.DAT [2006/08/02 12:57:56 | 000,231,821 | ---- | C] () -- C:\WINDOWS\System32\CTSBASW.DAT [2006/08/02 12:57:56 | 000,140,643 | ---- | C] () -- C:\WINDOWS\System32\CTBAS2W.DAT [2006/08/02 12:57:56 | 000,113,221 | ---- | C] () -- C:\WINDOWS\System32\CTBASICW.DAT [2006/08/02 12:57:56 | 000,038,400 | ---- | C] () -- C:\WINDOWS\System32\CTBURST.DLL [2006/08/02 12:57:56 | 000,034,304 | ---- | C] () -- C:\WINDOWS\PSCONV.EXE [2006/08/02 12:57:56 | 000,033,792 | ---- | C] () -- C:\WINDOWS\System32\REGPLIB.EXE [2006/08/02 12:57:56 | 000,000,194 | ---- | C] () -- C:\WINDOWS\System32\KILL.INI [2006/08/02 12:57:56 | 000,000,053 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini [2006/08/02 12:57:54 | 000,050,432 | ---- | C] () -- C:\WINDOWS\System32\claptn.ini [2006/08/02 12:56:50 | 000,049,152 | ---- | C] () -- C:\WINDOWS\setpwrcg.exe [2006/08/02 12:56:46 | 000,114,630 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat [2006/08/02 12:56:24 | 000,000,392 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI [2006/05/02 17:38:24 | 000,072,444 | ---- | C] () -- C:\WINDOWS\SetBrowser.exe [2006/05/02 17:38:24 | 000,000,748 | ---- | C] () -- C:\WINDOWS\SetBrowser.ini [2005/11/10 07:56:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini [2005/08/02 13:00:16 | 000,000,611 | ---- | C] () -- C:\WINDOWS\System32\dlccplc.ini [2004/08/10 12:12:05 | 000,000,780 | ---- | C] () -- C:\WINDOWS\orun32.ini [2004/08/10 12:07:31 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2004/08/10 12:02:15 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2004/08/10 12:01:18 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini [2004/08/10 11:57:52 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2004/08/10 11:57:15 | 000,325,912 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2004/08/10 11:51:21 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat [2004/08/10 11:51:20 | 000,463,720 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat [2004/08/10 11:51:20 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat [2004/08/10 11:51:20 | 000,080,848 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat [2004/08/10 11:51:20 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat [2004/08/10 11:51:18 | 000,004,627 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat [2004/08/10 11:51:17 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin [2004/08/10 11:51:16 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat [2004/08/10 11:51:12 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat [2004/08/10 11:51:11 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin [2004/08/10 11:51:05 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat [2004/08/10 11:50:56 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin [2003/01/07 14:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI [color=#E56717]========== Files - Unicode (All) ==========[/color] [2011/12/09 23:41:24 | 000,000,000 | ---- | M] ()(C:\Documents and Settings\Jill\Desktop\????????????????) -- C:\Documents and Settings\Jill\Desktop\喝ᓝ橡矶圀ई햜ਔ핬ਔ睐�㵻햜ਔ [2011/12/09 23:41:24 | 000,000,000 | ---- | C] ()(C:\Documents and Settings\Jill\Desktop\????????????????) -- C:\Documents and Settings\Jill\Desktop\喝ᓝ橡矶圀ई햜ਔ핬ਔ睐�㵻햜ਔ < End of report >