Here we go:
OTL logfile created on: 3/13/2012 11:07:47 PM - Run 2
OTL by OldTimer - Version 3.2.36.3 Folder = C:\Documents and Settings\williams\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 2.35 Gb Available Physical Memory | 78.47% Memory free
4.83 Gb Paging File | 4.27 Gb Available in Paging File | 88.41% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 634.76 Gb Total Space | 422.39 Gb Free Space | 66.54% Space Free | Partition Type: NTFS
Drive D: | 296.75 Gb Total Space | 149.29 Gb Free Space | 50.31% Space Free | Partition Type: NTFS
Drive R: | 1.92 Gb Total Space | 0.30 Gb Free Space | 15.46% Space Free | Partition Type: FAT
Computer Name: ASUS-I7-XP | User Name: williams | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/03/11 01:05:14 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\williams\Desktop\google.exe
PRC - [2012/02/20 07:10:31 | 005,860,984 | ---- | M] (SlySoft, Inc.) -- C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
PRC - [2012/02/14 16:03:14 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\williams\Application Data\Dropbox\bin\Dropbox.exe
PRC - [2011/12/28 13:22:34 | 000,995,328 | ---- | M] (Seattle Avionics, Inc.) -- C:\Program Files\Seattle Avionics\Data Manager\DataManager.exe
PRC - [2011/11/15 10:20:26 | 000,095,608 | ---- | M] (Dyn, Inc.) -- C:\Program Files\DynDNS Updater\DynUpSvc.exe
PRC - [2011/11/15 10:20:26 | 000,078,192 | ---- | M] (Dyn, Inc.) -- C:\Program Files\DynDNS Updater\DynTray.exe
PRC - [2011/09/29 10:59:42 | 000,022,016 | ---- | M] (Altaro) -- C:\Program Files\Altaro\Oops!Backup\OopsBackup.Service.exe
PRC - [2011/06/15 15:16:48 | 000,997,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/04/27 15:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2010/12/16 12:57:20 | 000,956,416 | ---- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) -- C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
PRC - [2010/11/05 23:54:22 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/11/05 23:54:20 | 000,283,160 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
PRC - [2010/04/06 10:29:24 | 000,462,848 | ---- | M] () -- C:\Program Files\SmartDraw VP\Messages\SDNotify.exe
PRC - [2010/04/01 02:16:20 | 000,357,696 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
PRC - [2009/11/11 16:17:02 | 000,771,360 | ---- | M] (Apple Inc.) -- C:\Program Files\AirPort\APAgent.exe
PRC - [2008/04/14 05:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/01/31 15:55:42 | 000,096,370 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2005/11/28 14:02:56 | 000,988,701 | ---- | M] (Acronis) -- C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
PRC - [2005/11/28 14:02:54 | 000,172,032 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
PRC - [2005/11/28 14:02:54 | 000,118,784 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2003/05/15 01:19:50 | 000,217,193 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
PRC - [2000/11/01 15:02:40 | 000,821,248 | ---- | M] (Insight Software Solutions, Inc.) -- C:\Program Files\Capture Express\CAPEXP.EXE
========== Modules (No Company Name) ========== MOD - [2012/02/16 04:09:45 | 001,712,128 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\96e485c02ad346a2bd26a635e7fcb023\Microsoft.VisualBasic.ni.dll
MOD - [2012/02/16 04:08:45 | 000,169,984 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IsdiInterop\b3e81fd9c1ade6e33caecc88a8fa6852\IsdiInterop.ni.dll
MOD - [2012/02/16 04:08:39 | 011,817,472 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\29bdc8352d3c26e3c572ea60639dec3b\System.Web.ni.dll
MOD - [2012/02/16 04:08:35 | 000,771,584 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\c14e58265386feb509cc61bb5e8dd296\System.Runtime.Remoting.ni.dll
MOD - [2012/02/16 04:08:34 | 000,475,136 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IAStorUtil\0b1511cce24703a70176793a84157d6c\IAStorUtil.ni.dll
MOD - [2012/02/16 04:08:34 | 000,218,624 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IAStorDataMgr\fc601f9ac8267faabddf6356592707cb\IAStorDataMgr.ni.dll
MOD - [2012/02/16 04:08:33 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\11dcb806c92f55111f5fa9f1a90e3bdd\System.ServiceProcess.ni.dll
MOD - [2012/02/16 04:08:30 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\94a40f415bfa947e251888bbe88bb973\System.Configuration.ni.dll
MOD - [2012/02/16 04:08:29 | 000,019,968 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IAStorDataMgrSvc\aa0eef53ddfffe7448c69e4c5e3cc8ae\IAStorDataMgrSvc.ni.exe
MOD - [2012/02/16 04:07:02 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\77e1279cbf4eecfb0284b63316fe43fe\System.Xml.ni.dll
MOD - [2012/02/16 04:06:59 | 012,430,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ad99ac6b5666edb8ee742dd64f9578af\System.Windows.Forms.ni.dll
MOD - [2012/02/16 04:06:51 | 001,587,200 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\9351cf29bb1ba951e45a9b3b0edab937\System.Drawing.ni.dll
MOD - [2012/02/16 04:06:42 | 006,616,576 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Data\ae888f8633fce3ff1de98e32bce0abbf\System.Data.ni.dll
MOD - [2012/02/16 04:06:10 | 003,325,440 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsBase\174c2f776741812aed02c337bbcd1dae\WindowsBase.ni.dll
MOD - [2012/02/16 04:06:04 | 007,953,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\9e3803cd2a11f056291862e306a8e2b2\System.ni.dll
MOD - [2012/02/16 04:05:36 | 002,933,248 | ---- | M] () -- C:\WINDOWS\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2011/12/28 13:22:28 | 000,016,384 | ---- | M] () -- C:\Program Files\Seattle Avionics\Data Manager\CRC32.dll
MOD - [2011/10/13 03:07:14 | 000,014,336 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IAStorCommon\eb908ce5af4529075e181e94c4587e87\IAStorCommon.ni.dll
MOD - [2011/10/13 03:06:59 | 000,025,600 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\d86a3346c3d90ff12d0df9d7726f3ece\Accessibility.ni.dll
MOD - [2011/10/13 03:04:39 | 011,490,816 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\ca87ba84221991839abbe7d4bc9c6721\mscorlib.ni.dll
MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/12/16 12:36:18 | 000,315,392 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libtidy.dll
MOD - [2010/12/16 12:36:16 | 000,433,664 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libxml2.dll
MOD - [2010/12/16 12:36:10 | 000,200,704 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libpcre.dll
MOD - [2010/11/05 23:50:02 | 000,058,880 | ---- | M] () -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
MOD - [2010/10/20 15:45:26 | 008,801,120 | ---- | M] () -- C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2010/04/06 10:29:24 | 000,462,848 | ---- | M] () -- C:\Program Files\SmartDraw VP\Messages\SDNotify.exe
MOD - [2007/03/29 15:48:21 | 000,022,723 | R--- | M] () -- C:\WINDOWS\system32\ml285pl3.dll
MOD - [1999/09/08 17:24:04 | 000,031,232 | ---- | M] () -- C:\Program Files\Capture Express\QCAPHK.DLL
========== Win32 Services (SafeList) ========== SRV - [2011/11/15 10:20:26 | 000,095,608 | ---- | M] (Dyn, Inc.) [Auto | Running] -- C:\Program Files\DynDNS Updater\DynUpSvc.exe -- (Dyn Updater)
SRV - [2011/09/29 10:59:42 | 000,022,016 | ---- | M] (Altaro) [Auto | Running] -- C:\Program Files\Altaro\Oops!Backup\OopsBackup.Service.exe -- (OopsBackup.Service.exe)
SRV - [2011/09/19 19:29:43 | 000,597,281 | ---- | M] () [Auto | Stopped] -- C:\Program Files\emailrelay\emailrelay-service.exe -- (emailrelay)
SRV - [2011/05/21 06:01:00 | 002,214,504 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/04/27 15:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2010/11/05 23:54:22 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel(R)
SRV - [2010/06/25 10:07:20 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2009/11/23 15:28:28 | 000,683,008 | ---- | M] (Synametrics Technologies) [Auto | Stopped] -- C:\Programs\DeltaCopy\DCServce.exe -- (DeltaCopyService)
SRV - [2008/04/17 10:08:46 | 001,528,608 | ---- | M] (Cisco Systems, Inc.) [Auto | Stopped] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
SRV - [2007/01/31 15:55:42 | 000,096,370 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2006/01/05 00:06:02 | 000,163,840 | ---- | M] (Alex Feinman) [On_Demand | Stopped] -- C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe -- (Imapi Helper)
SRV - [2005/11/28 14:02:54 | 000,172,032 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | Auto | Stopped] -- -- (SSPORT)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | Auto | Stopped] -- -- (DgiVecp)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (catchme)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (ats1rxlf)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (aswMBR)
DRV - File not found [Kernel | Auto | Stopped] -- -- (ASPI32)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (ALSysIO)
DRV - [2012/01/29 13:22:55 | 000,121,208 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2010/10/14 07:48:52 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010/06/25 10:07:14 | 000,035,088 | ---- | M] (CACE Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2010/02/01 13:10:50 | 000,024,344 | ---- | M] (SMART Modular) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\JeppDrive.sys -- (JEPPDRIVE)
DRV - [2009/12/18 10:58:52 | 000,011,336 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\SystemRequirementsLab\cpudrv.sys -- (cpudrv)
DRV - [2009/10/04 11:28:47 | 000,217,664 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\truecrypt.sys -- (truecrypt)
DRV - [2009/08/29 19:46:44 | 000,249,152 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\timntr.sys -- (timounter)
DRV - [2009/08/29 19:46:44 | 000,030,688 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2009/08/29 19:46:43 | 000,096,320 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\snapman.sys -- (snapman)
DRV - [2009/03/27 02:16:28 | 000,012,672 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\cpuz132_x32.sys -- (cpuz132)
DRV - [2008/11/18 12:27:58 | 000,083,296 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\jraid.sys -- (JRAID)
DRV - [2008/07/03 17:03:14 | 004,745,216 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/04/17 10:07:52 | 000,306,299 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys -- (CVPNDRVA)
DRV - [2008/03/29 18:36:28 | 000,125,328 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\dne2000.sys -- (DNE)
DRV - [2008/02/09 20:58:00 | 000,066,736 | R--- | M] (Silicon Image, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\pnp680.sys -- (Pnp680)
DRV - [2007/12/17 18:14:06 | 000,012,400 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AsIO.sys -- (AsIO)
DRV - [2007/05/31 07:19:22 | 000,096,896 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2007/01/18 18:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CVirtA.sys -- (CVirtA)
DRV - [2006/11/22 06:20:00 | 000,072,704 | ---- | M] (WIBU-SYSTEMS AG) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\WibuKey.sys -- (WIBUKEY)
DRV - [2006/11/09 06:20:00 | 000,016,384 | ---- | M] (WIBU-SYSTEMS AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Wibukey2.sys -- (Wibukey2)
DRV - [2005/07/25 10:04:08 | 000,048,640 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ser2pl.sys -- (Ser2pl)
DRV - [2004/08/13 11:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\..\SearchScopes,DefaultScope = {65497A31-B9C8-47B3-A77C-A65B6E43BF95}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRCIE - HKCU\..\SearchScopes\{65497A31-B9C8-47B3-A77C-A65B6E43BF95}: "URL" =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "
http://www.google.com"
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {aff87fa2-a58e-4edd-b852-0a20203c1e17}:0.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.http: "192.168.1.4"
FF - prefs.js..network.proxy.http_port: 9999
FF - prefs.js..network.proxy.type: 4
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/24 20:10:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/01/12 08:54:25 | 000,000,000 | ---D | M]
[2009/09/03 22:44:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\williams\Application Data\Mozilla\Extensions
[2009/09/03 22:44:19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\williams\Application Data\Mozilla\Extensions\
mozswing@mozswing.org[2012/02/16 08:56:40 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\williams\Application Data\Mozilla\Firefox\Profiles\9g2mvweg.default\extensions
[2011/09/13 23:39:15 | 000,000,000 | ---D | M] (Garmin Communicator) -- C:\Documents and Settings\williams\Application Data\Mozilla\Firefox\Profiles\9g2mvweg.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2010/05/11 21:23:06 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\williams\Application Data\Mozilla\Firefox\Profiles\9g2mvweg.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/08/30 09:26:14 | 000,002,399 | ---- | M] () -- C:\Documents and Settings\williams\Application Data\Mozilla\Firefox\Profiles\9g2mvweg.default\searchplugins\daemon-search.xml
[2012/01/10 10:02:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
() (No name found) -- C:\DOCUMENTS AND SETTINGS\WILLIAMS\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\9G2MVWEG.DEFAULT\EXTENSIONS\{AFF87FA2-A58E-4EDD-B852-0A20203C1E17}.XPI
[2011/06/16 07:08:09 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/02/24 20:10:15 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/07 20:13:56 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2012/02/24 20:10:12 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/24 20:10:12 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - Extension: Entanglement = C:\Documents and Settings\williams\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.1.1_0\
CHR - Extension: Poppit = C:\Documents and Settings\williams\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
O1 HOSTS File: ([2012/03/12 12:57:34 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AirPort Base Station Agent] C:\Program Files\AirPort\APAgent.exe (Apple Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DNS7reminder] C:\Program Files\Nuance\NaturallySpeaking10\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [HP Lamp] C:\SCANJET\PrecisionScanPro\HPLamp.exe File not found
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NBKeyScan] C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\nvmctray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe (Acronis)
O4 - HKCU..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe (SlySoft, Inc.)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Oops!Backup] C:\Program Files\Altaro\Oops!Backup\OopsBackup.exe (Altaro)
O4 - HKCU..\Run: [Seattle Avionics Data Manager] C:\Program Files\Seattle Avionics\Data Manager\DataManager.exe (Seattle Avionics, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe (Adobe Systems Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Dyn Updater Tray Icon.lnk = C:\Program Files\DynDNS Updater\DynTray.exe (Dyn, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Evernote Clipper.lnk = C:\WINDOWS\Installer\{F761359C-9CED-45AE-9A51-9D6605CD55C4}\Evernote.ico ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk = C:\WINDOWS\Installer\{4C271126-C295-4828-A901-5910AE0C258B}\Icon3E5562ED7.ico ()
O4 - Startup: C:\Documents and Settings\williams\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\williams\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Documents and Settings\williams\Start Menu\Programs\Startup\Shortcut to CAPEXP.lnk = C:\Program Files\Capture Express\CAPEXP.EXE (Insight Software Solutions, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044}
http://lumahai.dyndns.org/activex/AMC.cab (AxisMediaControlEmb Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5BCB5AC2-47E7-4067-BB2B-3D43F96FC119}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FC0D2F06-D88B-4C0E-AB2A-2C7298748C71}: NameServer = 206.13.28.12,206.13.31.12
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\williams\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\williams\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Program Files\eudora51\EuShlExt.dll (Qualcomm Inc.)
O30 - LSA: Authentication Packages - (relog_ap) - C:\WINDOWS\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/07 19:58:26 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2012/03/12 23:18:30 | 004,730,880 | ---- | C] (AVAST Software) -- C:\Documents and Settings\williams\Desktop\aswMBR.exe
[2012/03/12 22:16:22 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/03/12 22:13:08 | 002,063,920 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\williams\Desktop\tdsskiller.exe
[2012/03/12 19:04:55 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2012/03/12 12:35:47 | 000,000,000 | ---D | C] -- C:\gotcha
[2012/03/12 08:12:16 | 004,434,343 | R--- | C] (Swearware) -- C:\Documents and Settings\williams\Desktop\gotcha.exe
[2012/03/12 00:00:33 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/03/11 01:16:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\williams\Desktop\RK_Quarantine
[2012/03/11 01:15:13 | 000,594,944 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\williams\Desktop\google.exe
[2012/03/10 20:49:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\setup.pss
[2012/03/10 19:50:46 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/03/10 19:50:46 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/03/10 19:50:46 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/03/10 19:50:46 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/03/10 19:50:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/03/10 19:50:25 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/03/09 23:49:20 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2012/03/09 09:22:19 | 000,000,000 | R--D | C] -- C:\Documents and Settings\williams\Start Menu\Programs\Administrative Tools
[2012/03/09 03:04:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2012/03/08 20:20:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2012/03/08 19:48:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Core Temp
[2012/03/08 19:48:45 | 000,000,000 | ---D | C] -- C:\Program Files\Core Temp
[2012/03/08 10:15:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\williams\Application Data\Malwarebytes
[2012/03/08 10:15:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/03/08 10:15:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/03/08 10:15:30 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/03/08 10:15:30 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/03/08 09:52:50 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2012/03/08 09:35:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\williams\Start Menu\Programs\Smart Fortress 2012
[2012/03/08 09:31:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\99058D500033A0A4005FA5A6D151FC4E
[2012/02/29 23:07:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2012/02/29 23:07:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2012/02/15 10:39:35 | 000,000,000 | R--D | C] -- C:\Documents and Settings\williams\My Documents\Dropbox
[2012/02/15 10:36:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\williams\Start Menu\Programs\Dropbox
[2012/02/15 10:36:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\williams\Application Data\Dropbox
========== Files - Modified Within 30 Days ========== [2012/03/13 23:09:58 | 000,462,914 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/03/13 23:09:58 | 000,079,116 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/03/13 23:08:22 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2012/03/13 23:05:49 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/03/13 23:05:29 | 000,002,447 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
[2012/03/13 23:05:29 | 000,002,349 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Evernote Clipper.lnk
[2012/03/13 23:05:14 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/13 23:05:11 | 000,000,478 | ---- | M] () -- C:\WINDOWS\tasks\SDMsgUpdate (TE).job
[2012/03/13 23:03:17 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/03/13 21:19:10 | 000,000,890 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/12 23:06:24 | 004,730,880 | ---- | M] (AVAST Software) -- C:\Documents and Settings\williams\Desktop\aswMBR.exe
[2012/03/12 22:08:22 | 002,063,920 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\williams\Desktop\tdsskiller.exe
[2012/03/12 12:57:34 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/03/12 08:01:12 | 004,434,343 | R--- | M] (Swearware) -- C:\Documents and Settings\williams\Desktop\gotcha.exe
[2012/03/11 01:05:14 | 000,594,944 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\williams\Desktop\google.exe
[2012/03/11 01:03:14 | 001,219,072 | ---- | M] () -- C:\Documents and Settings\williams\Desktop\RogueKiller.exe
[2012/03/08 23:35:23 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/03/08 20:21:44 | 000,001,813 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2012/03/08 19:48:46 | 000,000,818 | ---- | M] () -- C:\Documents and Settings\williams\Desktop\Core Temp.lnk
[2012/03/08 10:26:52 | 000,000,552 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[2012/03/08 10:15:32 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/08 10:01:41 | 000,000,633 | ---- | M] () -- C:\Documents and Settings\williams\My Documents\fixexe.zip
[2012/03/08 09:59:06 | 000,000,633 | ---- | M] () -- C:\Documents and Settings\williams\Desktop\fixexe.zip
[2012/03/01 00:56:42 | 000,001,027 | ---- | M] () -- C:\Documents and Settings\williams\Start Menu\Programs\Startup\Dropbox.lnk
[2012/03/01 00:56:42 | 000,001,027 | ---- | M] () -- C:\Documents and Settings\williams\Desktop\Dropbox.lnk
[2012/03/01 00:10:00 | 000,000,361 | ---- | M] () -- C:\Documents and Settings\williams\My Documents\fixexe.inf
[2012/03/01 00:10:00 | 000,000,326 | ---- | M] () -- C:\Documents and Settings\williams\My Documents\fixexe.reg
[2012/02/27 12:36:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/02/21 09:56:14 | 000,000,754 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AnyDVD.lnk
[2012/02/18 13:56:29 | 000,001,480 | ---- | M] () -- C:\WINDOWS\AUTOLNCH.REG
[2012/02/16 08:55:19 | 000,269,392 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/16 04:01:33 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
========== Files Created - No Company Name ========== [2012/03/11 01:15:09 | 001,219,072 | ---- | C] () -- C:\Documents and Settings\williams\Desktop\RogueKiller.exe
[2012/03/10 19:50:46 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/03/10 19:50:46 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/03/10 19:50:46 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/03/10 19:50:46 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/03/10 19:50:46 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/03/08 19:48:46 | 000,000,818 | ---- | C] () -- C:\Documents and Settings\williams\Desktop\Core Temp.lnk
[2012/03/08 10:26:52 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2012/03/08 10:15:32 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/08 10:02:48 | 000,000,361 | ---- | C] () -- C:\Documents and Settings\williams\My Documents\fixexe.inf
[2012/03/08 10:02:48 | 000,000,326 | ---- | C] () -- C:\Documents and Settings\williams\My Documents\fixexe.reg
[2012/03/08 10:01:41 | 000,000,633 | ---- | C] () -- C:\Documents and Settings\williams\My Documents\fixexe.zip
[2012/03/08 09:58:56 | 000,000,633 | ---- | C] () -- C:\Documents and Settings\williams\Desktop\fixexe.zip
[2012/02/21 09:56:14 | 000,000,754 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AnyDVD.lnk
[2012/02/15 10:39:35 | 000,001,027 | ---- | C] () -- C:\Documents and Settings\williams\Desktop\Dropbox.lnk
[2012/02/15 10:37:17 | 000,001,027 | ---- | C] () -- C:\Documents and Settings\williams\Start Menu\Programs\Startup\Dropbox.lnk
[2012/02/15 04:42:51 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/02/15 04:42:51 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\dllcache\iacenc.dll
[2011/10/23 15:05:30 | 000,273,344 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/10/23 15:05:30 | 000,273,344 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/10/23 15:05:30 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/05/21 06:01:00 | 002,123,582 | ---- | C] () -- C:\WINDOWS\System32\nvdata.data
[2011/04/10 08:36:50 | 000,423,520 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/04/04 23:05:42 | 000,000,183 | ---- | C] () -- C:\Documents and Settings\williams\Application Data\PropCalc Preferences
[2010/10/14 07:56:57 | 008,977,408 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\toolboxDatabase
[2010/10/10 19:17:42 | 000,008,192 | ---- | C] () -- C:\Documents and Settings\williams\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/13 18:55:36 | 000,022,723 | R--- | C] () -- C:\WINDOWS\System32\ml285pl3.dll
[2010/06/25 10:03:12 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2010/05/02 23:18:12 | 000,000,748 | ---- | C] () -- C:\WINDOWS\GARMINWT.INI
[2010/04/29 08:30:09 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/04/29 08:18:45 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
========== LOP Check ========== [2012/03/08 09:31:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\99058D500033A0A4005FA5A6D151FC4E
[2011/01/25 23:48:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Altaro
[2010/10/14 07:48:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2011/10/22 14:09:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Dyn
[2009/12/31 12:13:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DynDNS
[2009/08/30 23:50:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Elaborate Bytes
[2010/01/01 11:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nuance
[2012/03/13 23:05:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\OopsBackup
[2010/04/25 17:36:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/08/30 23:38:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SlySoft
[2011/09/18 14:21:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tomvale Aviation Calculator
[2011/05/09 23:00:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2010/04/14 22:09:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/10/04 11:47:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/08/15 18:30:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2011/05/28 09:09:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\Amazon
[2011/04/05 19:51:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\calibre
[2009/04/12 12:37:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\DAEMON Tools
[2009/08/30 09:27:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\DAEMON Tools Lite
[2009/04/12 12:37:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\DAEMON Tools Pro
[2012/03/13 23:05:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\Dropbox
[2011/06/16 08:02:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\ElevatedDiagnostics
[2010/01/07 20:06:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\Foxit
[2010/07/26 22:15:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\Foxit Software
[2010/05/15 09:23:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\GARMIN
[2010/10/14 07:51:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\GetRightToGo
[2010/05/23 11:02:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\GPS Utility
[2011/03/22 22:26:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\gtk-2.0
[2010/10/17 17:28:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\MechanicToolboxPreferences
[2009/08/30 14:08:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\Milestone
[2010/01/01 11:27:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\Nuance
[2009/08/15 13:31:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\Publish Providers
[2009/09/02 20:16:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\Qualcomm
[2010/04/25 17:36:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\ScanSoft
[2010/08/26 22:59:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\Seattle Avionics
[2011/06/04 12:41:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\SmartDraw
[2009/08/15 13:31:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\Sony
[2010/01/07 20:41:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\SSH
[2011/03/25 22:52:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\SystemRequirementsLab
[2011/09/28 09:10:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\Taunton
[2009/10/04 11:32:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\TrueCrypt
[2010/01/03 14:30:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\UDC Profiles
[2011/10/23 15:04:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\Windows Desktop Search
[2011/11/13 19:24:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\williams\Application Data\Windows Search
[2012/03/13 23:08:22 | 000,000,424 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2012/03/13 23:05:11 | 000,000,478 | ---- | M] () -- C:\WINDOWS\Tasks\SDMsgUpdate (TE).job
========== Purity Check ========== < End of report >