OTL logfile created on: 10/27/2009 8:52:35 PM - Run 2
OTL by OldTimer - Version 3.0.22.1 Folder = C:\Documents and Settings\Larry\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
247.37 Mb Total Physical Memory | 81.68 Mb Available Physical Memory | 33.02% Memory free
604.37 Mb Paging File | 471.64 Mb Available in Paging File | 78.04% Paging File free
Paging file location(s): C:\pagefile.sys 372 744 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.23 Gb Total Space | 18.71 Gb Free Space | 54.65% Space Free | Partition Type: NTFS
Drive D: | 64.09 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DFS8FQ61
Current User Name: Larry
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Documents and Settings\Larry\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe (Dell Inc.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation)
========== Win32 Services (SafeList) ========== SRV - (AdobeActiveFileMonitor6.0 [On_Demand | Stopped]) -- C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32 [Auto | Running]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [On_Demand | Stopped]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (NetSvc [On_Demand | Stopped]) -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe (Intel(R) Corporation)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NICCONFIGSVC [Auto | Running]) -- C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe (Dell Inc.)
SRV - (Pml Driver HPZ12 [Auto | Running]) -- C:\WINDOWS\System32\HPZipm12.exe (HP)
SRV - (ThreatFire [Auto | Stopped]) -- File not found
SRV - (UMWdf [Auto | Running]) -- C:\WINDOWS\System32\wdfmgr.exe (Microsoft Corporation)
========== Driver Services (SafeList) ========== DRV - (AliIde [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (APPDRV [System | Running]) -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (asc [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (E100B [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (HPZid412 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (HSF_DP [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (HSFHWICH [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mraid35x [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (nv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) -- C:\WINDOWS\System32\DRIVERS\omci.sys (Dell Inc)
DRV - (pavboot [Boot | Running]) -- C:\WINDOWS\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RapFile [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\RapFile.sys (Internet Security Systems, Inc.)
DRV - (RapNet [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\RapNet.sys (Internet Security Systems, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (STAC97 [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (sym_hi [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (symc810 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (ultra [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (usbsermpt [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\usbsermpt.sys (Microsoft Corporation)
DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
========== Modules (SafeList) ========== MOD - C:\Documents and Settings\Larry\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll (Microsoft Corporation)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/mywayIE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page =
http://www.dell4me.com/mywayIE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell4me.com/mywayIE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/mywayIE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page =
http://www.dell4me.com/mywayIE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell4me.com/mywayIE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-727676555-7934855-426210013-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM32\blank.htm
IE - HKU\S-1-5-21-727676555-7934855-426210013-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKU\S-1-5-21-727676555-7934855-426210013-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/IE - HKU\S-1-5-21-727676555-7934855-426210013-1006\S-1-5-21-727676555-7934855-426210013-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.29
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.4
FF - prefs.js..extensions.enabledItems: {8585C31E-1E94-4498-ACEC-CB913A05FC52}:3.5.0
FF - prefs.js..extensions.enabledItems:
firefox@ghostery.com:2.0.1
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.8.8
FF - prefs.js..extensions.enabledItems: {455D905A-D37C-4643-A9E2-F6FEFAA0424A}:0.8.12
FF - prefs.js..extensions.enabledItems: {8e9008b4-ec7c-4c2a-828e-007d5d2dad22}:1.2
FF - prefs.js..extensions.enabledItems:
trackmenot@mrl.nyu.edu:0.6.2
FF - prefs.js..extensions.enabledItems: {37fa1426-b82d-11db-8314-0800200c9a66}:1.4.6
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20090414
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/10/27 20:27:22 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.4\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/10/27 20:15:00 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.4\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/10/27 20:15:00 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.21\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2009/07/13 21:44:09 | 00,000,000 | ---D | M]
[2008/08/21 20:15:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Extensions
[2008/08/21 20:15:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/10/27 20:26:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions
[2009/10/27 18:40:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
[2008/07/09 15:13:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{27A2FD41-CB23-4518-AB5C-C25BAFFDE531}
[2009/10/09 21:23:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
[2009/08/19 22:22:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}
[2009/09/17 19:04:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{4776510a-a1f4-41f3-a3c8-35b474ecef23}
[2009/10/27 18:40:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/06/07 17:14:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(2)
[2009/08/19 22:22:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{8585C31E-1E94-4498-ACEC-CB913A05FC52}
[2009/08/20 18:31:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{8e9008b4-ec7c-4c2a-828e-007d5d2dad22}
[2009/09/22 21:48:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2009/05/04 18:35:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}
[2009/07/28 18:44:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2009/08/19 22:22:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/05/04 18:35:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}
[2009/09/18 20:15:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/09/30 18:03:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\firebug@software.joehewitt.com
[2009/08/12 22:49:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\firefox@ghostery.com
[2009/04/20 20:02:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\hidemyass@scriptlance.com
[2009/09/17 19:04:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\trackmenot@mrl.nyu.edu
[2009/03/22 18:27:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Larry\Application Data\mozilla\Firefox\Profiles\447kj9mc.default\extensions\trustme@gness.com
[2009/10/20 21:28:35 | 00,002,136 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\Mozilla\FireFox\Profiles\447kj9mc.default\searchplugins\flickr-tags.xml
[2009/10/20 21:28:36 | 00,005,511 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\Mozilla\FireFox\Profiles\447kj9mc.default\searchplugins\foodtv.xml
[2008/06/22 06:13:21 | 00,001,712 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\Mozilla\FireFox\Profiles\447kj9mc.default\searchplugins\jeeves.xml
[2008/05/31 05:47:00 | 00,000,958 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\Mozilla\FireFox\Profiles\447kj9mc.default\searchplugins\scroogle.xml
[2008/05/10 21:14:14 | 00,000,705 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\Mozilla\FireFox\Profiles\447kj9mc.default\searchplugins\webster.xml
[2009/05/13 12:04:16 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/10/27 20:15:00 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/10/27 20:14:41 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/10/27 20:14:41 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/10/27 20:14:44 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2009/02/27 12:13:42 | 00,103,792 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2008/04/15 21:13:12 | 00,144,984 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2005/06/21 15:07:04 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2008/02/24 18:55:36 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2008/02/24 18:55:36 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2008/02/24 18:55:36 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2008/02/24 18:55:36 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2008/02/24 18:55:36 | 00,106,496 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2008/04/15 21:13:53 | 00,008,192 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprjplug.dll
[2008/04/15 21:12:59 | 00,094,208 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2009/09/13 10:44:00 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/09/13 10:44:00 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/09/13 10:44:00 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/09/13 10:44:00 | 00,002,344 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/09/13 10:44:00 | 00,002,371 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/09/13 10:44:00 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/09/13 10:44:00 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (331165 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1
www.007guard.comO1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1
www.008k.comO1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1
www.00hq.comO1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1
www.032439.comO1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1
www.0scan.comO1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1
www.1000gratisproben.comO1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1
www.1001namen.comO1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1
www.100888290cs.comO1 - Hosts: 127.0.0.1
www.100sexlinks.comO1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1
www.10sek.comO1 - Hosts: 127.0.0.1
www.1-2005-search.comO1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 11344 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (IAS Attribute Dictionary) - {6BC09692-0CE6-11D1-BAAE-00C04FC2E20D} - C:\WINDOWS\System32\iasrecst.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (IAS Netsh Jet Helper) - {6BC09693-0CE6-11D1-BAAE-00C04FC2E20D} - C:\WINDOWS\System32\iasrecst.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (IAS OLE-DB Data Store) - {6BC096C4-0CE6-11D1-BAAE-00C04FC2E20D} - C:\WINDOWS\System32\iasrecst.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AcrobatAccess Class) - {C523F39F-9C83-11D3-9094-00104BD0D535} - C:\Program Files\Adobe\Reader 9.0\Reader\plug_ins\Accessibility.api (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF Preview Handler for Vista) - {DC6EFB56-9CFA-464D-8880-44885D7DC193} - C:\Program Files\Adobe\Reader 9.0\Reader\pdfprevhndlr.dll (Adobe Systems, Inc.)
O3 - HKU\S-1-5-21-727676555-7934855-426210013-1006\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-727676555-7934855-426210013-1006\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKU\S-1-5-21-727676555-7934855-426210013-1006\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKU\S-1-5-21-727676555-7934855-426210013-1006\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-727676555-7934855-426210013-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-727676555-7934855-426210013-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKU\S-1-5-21-727676555-7934855-426210013-1006\..Trusted Domains: 8 domain(s) and sub-domain(s) not assigned to a zone.
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.106.192.61
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 11:04:08 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
========== Files/Folders - Created Within 30 Days ========== [15 C:\WINDOWS\System32\*.tmp files]
[2009/10/11 17:55:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/10/25 17:53:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/10/05 05:51:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Larry\Application Data\TrojanHunter
[2009/10/12 20:30:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Larry\Local Settings\Application Data\Comodo
[2009/10/27 20:23:05 | 00,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2009/10/25 13:16:48 | 00,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2009/10/27 20:22:53 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2009/10/12 20:53:16 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/10/04 17:09:47 | 00,000,000 | ---D | C] -- C:\Program Files\TrojanHunter 5.2
[2009/10/27 20:23:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2009/10/27 20:21:52 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpssvcs.dll
[2009/10/27 20:21:52 | 01,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/10/27 20:21:52 | 00,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/10/27 20:21:52 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsshhdr.dll
[2009/10/27 20:21:52 | 00,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/10/27 20:21:52 | 00,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\prntvpt.dll
[2009/10/27 20:21:52 | 00,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/10/27 20:21:51 | 00,000,000 | ---D | C] -- C:\7f2c0018bc7d5906607907428ec44e5f
[2009/10/27 19:00:33 | 00,026,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spupdsvc.exe
[2009/10/27 18:59:41 | 00,017,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll
[2009/10/26 22:12:36 | 00,521,728 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Larry\Desktop\OTL.exe
[2009/10/25 13:20:00 | 00,028,552 | ---- | C] (Panda Security, S.L.) -- C:\WINDOWS\System32\drivers\pavboot.sys
[2009/10/20 22:25:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Larry\Desktop\SysProt
[2009/10/19 21:49:33 | 00,000,000 | ---D | C] -- C:\rsit
========== Files - Modified Within 30 Days ========== [15 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/10/27 20:51:05 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/10/27 20:43:19 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/27 20:43:15 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/10/27 20:43:13 | 25,945,7024 | -HS- | M] () -- C:\hiberfil.sys
[2009/10/27 20:43:13 | 00,184,224 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/10/27 20:41:56 | 06,966,974 | -H-- | M] () -- C:\Documents and Settings\Larry\Local Settings\Application Data\IconCache.db
[2009/10/27 20:35:31 | 00,506,878 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/10/27 20:35:31 | 00,444,668 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/10/27 20:35:31 | 00,073,008 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/10/27 19:04:10 | 00,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/10/27 19:00:22 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/10/26 22:13:14 | 00,521,728 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Larry\Desktop\OTL.exe
[2009/10/25 12:16:27 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2009/10/24 09:48:38 | 00,061,678 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\PFP120JPR.{PB
[2009/10/24 09:48:38 | 00,012,358 | ---- | M] () -- C:\Documents and Settings\Larry\Application Data\PFP120JCM.{PB
[2009/10/24 09:47:44 | 00,002,516 | -HS- | M] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2009/10/24 09:00:01 | 00,000,306 | ---- | M] () -- C:\WINDOWS\tasks\WebReg Photosmart 2570 series.job
[2009/10/22 23:08:13 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\ISHARE
[2009/10/21 20:51:25 | 02,664,072 | ---- | M] () -- C:\Documents and Settings\Larry\Desktop\esetsmartinstaller_enu.exe
[2009/10/19 21:23:14 | 00,781,909 | ---- | M] () -- C:\Documents and Settings\Larry\Desktop\RSIT.exe
[2009/10/12 20:54:24 | 00,001,740 | ---- | M] () -- C:\Documents and Settings\Larry\Desktop\HijackThis.lnk
[2009/10/04 17:11:07 | 00,059,392 | R--- | M] () -- C:\WINDOWS\System32\streamhlp.dll
[2009/10/04 17:10:18 | 00,000,702 | ---- | M] () -- C:\Documents and Settings\Larry\Desktop\TrojanHunter.lnk
[2009/10/02 11:01:58 | 25,198,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/09/30 18:33:01 | 02,097,152 | ---- | M] () -- C:\Documents and Settings\Larry\My Documents\New Folder30_09_2009_18_33_08.sdb
========== Files - No Company Name ==========[2009/10/22 19:38:39 | 02,664,072 | ---- | C] () -- C:\Documents and Settings\Larry\Desktop\esetsmartinstaller_enu.exe
[2009/10/19 21:22:47 | 00,781,909 | ---- | C] () -- C:\Documents and Settings\Larry\Desktop\RSIT.exe
[2009/10/19 18:54:23 | 25,945,7024 | -HS- | C] () -- C:\hiberfil.sys
[2009/10/12 20:54:22 | 00,001,740 | ---- | C] () -- C:\Documents and Settings\Larry\Desktop\HijackThis.lnk
[2009/10/04 17:10:18 | 00,000,702 | ---- | C] () -- C:\Documents and Settings\Larry\Desktop\TrojanHunter.lnk
[2009/10/04 17:09:50 | 00,059,392 | R--- | C] () -- C:\WINDOWS\System32\streamhlp.dll
[2009/09/30 18:33:09 | 02,097,152 | ---- | C] () -- C:\Documents and Settings\Larry\My Documents\New Folder30_09_2009_18_33_08.sdb
[2009/08/01 15:19:15 | 00,000,131 | ---- | C] () -- C:\WINDOWS\CRC.INI
[2009/06/14 12:04:14 | 00,034,472 | ---- | C] () -- C:\Documents and Settings\Larry\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
[2009/06/14 12:04:14 | 00,000,227 | ---- | C] () -- C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2009/06/14 12:03:46 | 00,002,060 | ---- | C] () -- C:\Documents and Settings\Larry\Application Data\HPSU_48BitScanUpdate.log
[2009/06/14 12:03:46 | 00,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2009/06/14 11:39:18 | 00,000,000 | ---- | C] () -- C:\Documents and Settings\Larry\Application Data\HelpFilesUpdatePatch_HELPFILEREPLACE.log
[2009/06/14 11:39:17 | 00,000,352 | ---- | C] () -- C:\Documents and Settings\Larry\Application Data\HelpFilesUpdatePatch_PRINTHELPWRAPPER.log
[2009/06/14 11:39:17 | 00,000,234 | ---- | C] () -- C:\WINDOWS\PrnHlpLogConfig.ini
[2009/06/14 11:38:34 | 00,002,833 | ---- | C] () -- C:\Documents and Settings\Larry\Application Data\PatchUpdate_InstantShareJPG.log
[2009/06/14 11:38:34 | 00,000,214 | ---- | C] () -- C:\WINDOWS\HP_InstantSHareJPG.ini
[2009/06/14 11:37:34 | 00,003,623 | ---- | C] () -- C:\Documents and Settings\Larry\Application Data\PatchUpdate_IZClosingDiscError.log
[2009/06/14 11:37:34 | 00,000,217 | ---- | C] () -- C:\WINDOWS\HP_IZClosingDiscErrorPatch.ini
[2009/06/14 11:17:21 | 00,080,068 | ---- | C] () -- C:\Documents and Settings\Larry\Application Data\Update_HP_RedboxHprblog_HPSU.log
[2009/06/14 11:17:21 | 00,000,221 | ---- | C] () -- C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2009/06/14 00:37:51 | 00,000,130 | ---- | C] () -- C:\WINDOWS\cfplogvw.INI
[2008/09/18 22:11:31 | 00,000,000 | ---- | C] () -- C:\WINDOWS\hpqEmlSz.INI
[2008/06/17 21:17:18 | 00,000,000 | ---- | C] () -- C:\Program Files\temp01
[2008/04/17 12:15:44 | 06,966,974 | -H-- | C] () -- C:\Documents and Settings\Larry\Local Settings\Application Data\IconCache.db
[2008/04/09 16:54:20 | 00,095,589 | ---- | C] () -- C:\Program Files\Credentials-Large.jpg
[2007/12/02 20:13:54 | 00,000,367 | ---- | C] () -- C:\WINDOWS\Viewer.INI
[2007/12/02 20:12:29 | 00,086,304 | ---- | C] () -- C:\WINDOWS\RHVIDEO.DLL
[2007/04/28 13:51:48 | 00,064,512 | ---- | C] () -- C:\WINDOWS\System32\qrz32.dll
[2007/04/28 13:51:48 | 00,062,464 | ---- | C] () -- C:\WINDOWS\System32\agwdll32.dll
[2007/04/28 13:51:48 | 00,040,448 | ---- | C] () -- C:\WINDOWS\System32\RACCD32a.dll
[2007/04/28 13:51:48 | 00,026,112 | ---- | C] () -- C:\WINDOWS\System32\Hamcal32.dll
[2007/01/27 13:14:02 | 00,000,433 | ---- | C] () -- C:\WINDOWS\raccalbk.ini
[2006/08/17 14:04:10 | 00,000,010 | ---- | C] () -- C:\WINDOWS\System32\drivers\tmbi.sys
[2006/07/29 00:11:36 | 00,018,944 | ---- | C] () -- C:\WINDOWS\System32\ventmon.dll
[2006/06/18 09:27:15 | 00,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2005/12/25 22:12:54 | 00,000,657 | ---- | C] () -- C:\WINDOWS\cncscore.ini
[2005/12/25 22:12:38 | 00,000,470 | ---- | C] () -- C:\WINDOWS\superball.ini
[2005/12/04 20:14:16 | 00,000,477 | ---- | C] () -- C:\WINDOWS\Bible.INI
[2005/12/04 20:13:19 | 00,000,136 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/12/04 18:28:02 | 00,043,520 | ---- | C] () -- C:\Documents and Settings\Larry\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005/11/13 10:19:37 | 00,061,678 | ---- | C] () -- C:\Documents and Settings\Larry\Application Data\PFP120JPR.{PB
[2005/11/13 10:19:37 | 00,012,358 | ---- | C] () -- C:\Documents and Settings\Larry\Application Data\PFP120JCM.{PB
[2005/11/10 11:16:47 | 00,038,928 | ---- | C] () -- C:\Documents and Settings\Larry\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2005/11/10 11:16:45 | 00,000,128 | ---- | C] () -- C:\Documents and Settings\Larry\Local Settings\Application Data\fusioncache.dat
[2005/11/09 09:50:15 | 00,077,824 | R--- | C] () -- C:\WINDOWS\System32\hpzids01.dll
[2005/11/09 09:45:55 | 00,000,747 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2005/11/08 23:57:32 | 00,000,546 | ---- | C] () -- C:\WINDOWS\cdPlayer.ini
[2005/11/08 21:28:59 | 00,000,638 | ---- | C] () -- C:\WINDOWS\TTutor7.ini
[2005/11/08 21:12:25 | 00,000,069 | ---- | C] () -- C:\WINDOWS\encore_launcher.ini
[2005/11/08 19:23:34 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\Larry\Application Data\desktop.ini
[2005/11/08 11:44:28 | 00,002,516 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2005/11/08 11:44:28 | 00,000,056 | ---- | C] () -- C:\WINDOWS\System32\0D22A60220.sys
[2005/06/21 15:13:54 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/06/21 15:07:40 | 00,000,182 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/06/21 14:59:00 | 00,000,004 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare
[2005/06/21 14:58:06 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\SynTPCoI.dll
[2005/06/21 14:39:14 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\stac97co.dll
[2005/06/21 14:38:44 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
[2005/01/28 06:08:34 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/12/15 16:24:59 | 00,000,390 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2004/08/10 11:12:05 | 00,000,839 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/10 11:01:18 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/08/10 10:57:41 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2004/08/10 10:51:28 | 00,000,650 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/10 10:51:26 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2001/07/06 16:30:00 | 00,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
[2000/01/28 01:00:00 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
========== Alternate Data Streams ========== @Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:BC359956
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:061FEEDF
< End of report >