OTL logfile created on: 12/2/2010 4:51:09 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Carl\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.00 Mb Total Physical Memory | 250.00 Mb Available Physical Memory | 49.00% Memory free
864.00 Mb Paging File | 570.00 Mb Available in Paging File | 66.00% Paging File free
Paging file location(s): C:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.87 Gb Total Space | 18.48 Gb Free Space | 33.08% Space Free | Partition Type: FAT32
Computer Name: WINDOWS-xp1212 | User Name: Carl | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010/12/02 15:53:52 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Carl\desktop\OTL.exe
PRC - [2010/09/10 23:41:42 | 001,901,056 | ---- | M] (COMODO) -- C:\Utility.sys\Spyware - Comodo\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2010/09/10 23:41:20 | 002,500,552 | ---- | M] (COMODO) -- C:\Utility.sys\Spyware - Comodo\COMODO\COMODO Internet Security\cfp.exe
PRC - [2010/09/07 11:12:02 | 002,838,912 | ---- | M] (AVAST Software) -- C:\Utility.sys\Spyware - Avast\AvastUI.exe
PRC - [2010/09/07 11:12:00 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Utility.sys\Spyware - Avast\AvastSvc.exe
PRC - [2010/04/08 01:28:06 | 000,161,144 | R--- | M] (BUFFALO INC.) -- C:\Program Files\BUFFALO\SLManagerEasy\Inputps.exe
PRC - [2010/03/16 01:03:38 | 000,095,608 | R--- | M] (BUFFALO INC.) -- C:\Program Files\BUFFALO\SLManagerEasy\Bufssvr.exe
PRC - [2010/03/05 04:08:22 | 000,169,336 | R--- | M] (BUFFALO INC.) -- C:\Program Files\BUFFALO\BuffaloTools\BuffaloTools.exe
PRC - [2009/07/02 10:59:30 | 000,994,952 | ---- | M] (Acunetix Ltd.) -- C:\Utility.sys\Web Vulnerability Scanner 6\WVSScheduler.exe
PRC - [2008/10/07 16:25:50 | 000,095,744 | ---- | M] (j2 Global Communications, Inc.) -- C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
PRC - [2008/01/04 13:27:08 | 000,587,096 | ---- | M] (Lavasoft) -- C:\Utility.sys\Spyware Ad-Aware 2007\aawservice.exe
PRC - [2007/12/16 14:00:00 | 000,143,872 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE
PRC - [2007/06/13 06:23:08 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/02/16 12:58:12 | 000,856,064 | ---- | M] (Christian Diefer) -- C:\Utility.sys\I8kFanGui\I8kfanGUI.exe
PRC - [2007/01/10 14:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
PRC - [2006/11/13 13:39:52 | 001,289,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\wcescomm.exe
PRC - [2006/11/13 13:39:34 | 000,199,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\rapimgr.exe
PRC - [2005/08/12 19:34:52 | 000,733,184 | ---- | M] (D-Link) -- C:\Program Files\D-Link\AIRPLUS.exe
PRC - [2005/04/26 22:26:00 | 000,036,864 | ---- | M] () -- C:\WINDOWS\system32\acs.exe
PRC - [2005/04/06 16:03:28 | 000,110,592 | ---- | M] () -- C:\Telecom\_Iphone.dir\BlueTooth\BTNtService.exe
PRC - [2004/12/15 06:01:44 | 000,040,960 | ---- | M] (Vimicro) -- C:\WINDOWS\Vm_sti.exe
PRC - [2004/08/04 00:56:56 | 000,419,840 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\ntvdm.exe
PRC - [2001/09/19 11:20:34 | 000,245,760 | ---- | M] (ATI Technologies, Inc.) -- C:\WINDOWS\system32\atiptaxx.exe
========== Modules (SafeList) ==========
MOD - [2010/12/02 15:53:52 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Carl\desktop\OTL.exe
MOD - [2010/09/10 23:41:40 | 000,285,480 | ---- | M] (COMODO) -- C:\WINDOWS\system32\guard32.dll
MOD - [2010/03/04 12:17:08 | 000,057,344 | R--- | M] (BUFFALO INC.) -- C:\Program Files\BUFFALO\BuffaloTools\BuffaloTools.dll
MOD - [2006/08/25 11:45:56 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2010/09/10 23:41:42 | 001,901,056 | ---- | M] (COMODO) [Auto | Running] -- C:\Utility.sys\Spyware - Comodo\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2010/09/07 11:12:00 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Utility.sys\Spyware - Avast\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010/09/07 11:12:00 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Utility.sys\Spyware - Avast\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010/09/07 11:12:00 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Utility.sys\Spyware - Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/03/16 01:03:38 | 000,095,608 | R--- | M] (BUFFALO INC.) [Auto | Running] -- C:\Program Files\BUFFALO\SLManagerEasy\Bufssvr.exe -- (bufssvr)
SRV - [2009/07/02 10:59:30 | 000,994,952 | ---- | M] (Acunetix Ltd.) [Auto | Running] -- C:\Utility.sys\Web Vulnerability Scanner 6\WVSScheduler.exe -- (AcuWVSSchedulerv6)
SRV - [2008/01/04 13:27:08 | 000,587,096 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Utility.sys\Spyware Ad-Aware 2007\aawservice.exe -- (aawservice)
SRV - [2007/12/16 14:00:00 | 000,143,872 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40ST7.EXE -- (EPSON_EB_RPCV4_01) EPSON V5 Service4(01)
SRV - [2007/01/10 14:02:00 | 000,113,664 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE -- (EPSON_PM_RPCV4_01) EPSON V3 Service4(01)
SRV - [2005/04/26 22:26:00 | 000,036,864 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\acs.exe -- (ACS)
SRV - [2005/04/06 16:03:28 | 000,110,592 | ---- | M] () [Auto | Running] -- C:\Telecom\_Iphone.dir\BlueTooth\BTNtService.exe -- (BlueSoleil Hid Service)
SRV - [2005/01/29 18:29:16 | 000,173,040 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Utility.sys\SiSoftware Sandra Professional 2005.SR1\RpcDataSrv.exe -- (SandraDataSrv)
SRV - [2005/01/29 18:29:12 | 001,135,592 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Utility.sys\SiSoftware Sandra Professional 2005.SR1\RpcSandraSrv.exe -- (SandraTheSrv)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\SCFIDS~1\20070426.003\symidsco.sys -- (SYMIDSCO)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\jswimd.sys -- (jswimd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Carl\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - [2010/09/10 23:40:54 | 000,091,560 | ---- | M] (COMODO) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\inspect.sys -- (Inspect)
DRV - [2010/09/10 23:40:52 | 000,239,240 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2010/09/10 23:40:52 | 000,025,240 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2010/09/07 10:52:26 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010/09/07 10:52:04 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010/09/07 10:47:46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010/09/07 10:47:20 | 000,100,176 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010/09/07 10:47:08 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/09/07 10:46:52 | 000,028,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2010/01/16 08:40:26 | 000,010,624 | R--- | M] (BUFFALO INC.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\bftpusbx.sys -- (bftpusbx)
DRV - [2010/01/08 06:50:02 | 000,039,680 | R--- | M] (BUFFALO INC.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\bftpdskc.sys -- (bftpdskc)
DRV - [2007/02/16 05:05:48 | 000,014,464 | ---- | M] (Christian Diefer) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\fanio.sys -- (fanio)
DRV - [2006/09/24 09:28:46 | 000,005,248 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2005/10/23 17:25:12 | 000,023,000 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2005/10/23 17:21:42 | 000,010,068 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BtNetDrv.sys -- (BT)
DRV - [2005/08/31 10:34:52 | 000,020,480 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV - [2005/08/31 10:34:10 | 000,020,480 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2005/08/11 17:56:08 | 000,463,104 | ---- | M] (D-Link ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ar5211.sys -- (AR5211)
DRV - [2005/07/29 16:21:32 | 000,011,988 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VBTEnum.sys -- (BTHidEnum)
DRV - [2005/04/30 14:50:10 | 000,028,271 | ---- | M] (IVT Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\BTHidMgr.sys -- (BTHidMgr)
DRV - [2005/03/25 17:18:48 | 000,082,148 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VcommMgr.sys -- (VcommMgr)
DRV - [2004/12/16 16:32:54 | 000,013,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BTNetFilter.sys -- (BTNetFilter)
DRV - [2004/10/19 13:37:38 | 000,061,312 | ---- | M] (IVT Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\VComm.sys -- (VComm)
DRV - [2004/08/05 18:05:02 | 000,090,532 | ---- | M] (VM) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbVM31b.sys -- (ZSMC301b) Vimicro USB PC Camera (ZC0301PL)
DRV - [2004/08/03 23:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2003/06/17 11:03:00 | 000,079,360 | ---- | M] (Inprocomm, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\IPN2120.SYS -- (IPN2120)
DRV - [2003/05/01 15:10:10 | 000,316,272 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\fd_dmdm.sys -- (fd_dmdm)
DRV - [2003/05/01 15:09:58 | 000,015,248 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\fd_dmdfl.sys -- (fd_dmdfl)
DRV - [2003/05/01 15:08:48 | 000,173,584 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\fd_dbus.sys -- (fd_dbus) FutureDial USB Composite Device driver (WDM)
DRV - [2002/10/07 15:16:10 | 000,075,168 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2002/10/07 15:16:10 | 000,042,992 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2002/06/20 17:53:54 | 000,414,400 | ---- | M] (ESS Technology, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\es198xdl.sys -- (maestro) ESS Maestro Audio Driver (WDM)
DRV - [2002/06/13 14:08:46 | 000,014,604 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2002/05/02 12:52:22 | 000,017,134 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\PCANDIS5.SYS -- (PCANDIS5)
DRV - [2001/12/03 12:55:14 | 000,155,264 | ---- | M] (Zoran Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nuvvid2.sys -- (nuvvid2)
DRV - [2001/12/03 12:55:12 | 000,026,560 | ---- | M] (Zoran Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nuvaud2.sys -- (nuvaud2)
DRV - [2001/09/28 09:13:10 | 000,299,776 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mpab.sys -- (ati2mpab)
DRV - [2001/08/17 12:48:56 | 000,289,664 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\atimpab.sys -- (atimpab)
DRV - [2001/08/17 12:13:20 | 000,027,164 | ---- | M] (Xircom, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CE3N5.SYS -- (CE3)
DRV - [2001/08/17 12:11:06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\el90xbc5.sys -- (EL90XBC)
DRV - [2001/08/17 12:10:58 | 000,069,692 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\el575ND5.sys -- (el575nd5)
DRV - [2000/07/16 11:52:42 | 000,136,352 | ---- | M] (Nogatech Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Nuvision.sys -- (NUVision)
DRV - [1996/04/03 15:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledItems: {3205B348-523A-4fac-9BC4-9939CBF583B0}:2.1.5
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.1
FF - prefs.js..extensions.enabledItems: {8A6C82A1-F6C9-481a-AAE7-C96444C9A754}:5.1.1
FF - prefs.js..extensions.enabledItems:
personas@christopher.beard:1.5.2
FF - prefs.js..extensions.enabledItems: {2A1D5949-B519-4924-BF62-8522FE0D5274}:0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..keyword.URL: "http://www.google.com/search?ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..network.proxy.backup.ftp: ""
FF - prefs.js..network.proxy.backup.ftp_port: 0
FF - prefs.js..network.proxy.backup.gopher: ""
FF - prefs.js..network.proxy.backup.gopher_port: 0
FF - prefs.js..network.proxy.backup.socks: "127.0.0.1"
FF - prefs.js..network.proxy.backup.socks_port: 81
FF - prefs.js..network.proxy.backup.ssl: "127.0.0.1"
FF - prefs.js..network.proxy.backup.ssl_port: 81
FF - prefs.js..network.proxy.ftp: "localhost"
FF - prefs.js..network.proxy.ftp_port: 4777
FF - prefs.js..network.proxy.gopher: "localhost"
FF - prefs.js..network.proxy.gopher_port: 4777
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 4777
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.ssl: "localhost"
FF - prefs.js..network.proxy.ssl_port: 4777
FF - prefs.js..network.proxy.type: 1
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Firefox\components [2007/07/17 13:29:10 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Firefox\plugins [2007/07/17 13:29:10 | 000,000,000 | ---D | M]
[2008/09/05 15:38:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Mozilla\Extensions
[2010/09/08 22:30:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Carl\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2007/07/17 13:29:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\extensions
[2010/09/11 11:38:40 | 000,000,000 | ---D | M] (PDFescape Extension) -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\extensions\{2A1D5949-B519-4924-BF62-8522FE0D5274}
[2010/08/15 18:51:18 | 000,000,000 | ---D | M] (Old Location Bar) -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\extensions\{3205B348-523A-4fac-9BC4-9939CBF583B0}
[2009/10/15 23:05:18 | 000,000,000 | ---D | M] (PDF Download) -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2010/08/17 13:01:42 | 000,000,000 | ---D | M] (PrefBar) -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\extensions\{8A6C82A1-F6C9-481a-AAE7-C96444C9A754}
[2010/02/11 14:00:22 | 000,000,000 | ---D | M] (Live HTTP Headers) -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}
[2010/09/18 22:18:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\extensions\CertPatrol@PSYC(2).EU
[2010/09/23 05:02:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\extensions\en-US@dictionaries.addons.mozilla(2).org
[2010/10/08 18:01:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\extensions\es-es@dictionaries.addons.mozilla(2).org
[2010/03/21 19:00:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\extensions\personas@christopher.beard
[2009/10/31 11:53:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\extensions\seo4firefox@seobook(2).com
[2010/09/24 22:02:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\extensions\unplug@compunach(2)
[2010/11/16 15:50:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\extensions\unplug@compunach(3)
[2008/06/03 10:39:54 | 000,001,340 | ---- | M] () -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\searchplugins\bbc-news.xml
[2008/06/24 16:58:20 | 000,000,681 | ---- | M] () -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\searchplugins\webster.xml
[2009/06/21 22:29:28 | 000,002,246 | ---- | M] () -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\searchplugins\espn.xml
[2008/06/24 16:58:14 | 000,001,712 | ---- | M] () -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\searchplugins\askcom.xml
[2007/07/17 15:34:08 | 000,001,035 | ---- | M] () -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\searchplugins\usatodaycom.xml
[2008/06/24 16:58:22 | 000,001,108 | ---- | M] () -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\searchplugins\wikipedia-en.xml
[2007/07/17 16:01:00 | 000,002,095 | ---- | M] () -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\searchplugins\expediacom.xml
[2007/07/17 16:01:22 | 000,001,437 | ---- | M] () -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\searchplugins\yahoo-answers.xml
[2007/10/10 21:08:16 | 000,001,355 | ---- | M] () -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\searchplugins\godaddycom.xml
[2010/11/26 18:49:52 | 000,002,143 | ---- | M] () -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\searchplugins\marketwatch.xml
[2010/11/26 18:49:52 | 000,001,835 | ---- | M] () -- C:\Documents and Settings\Carl\Application Data\Mozilla\Firefox\Profiles\sqfvpfgm.default\searchplugins\weathercom.xml
O1 HOSTS File: ([2010/12/01 15:11:04 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\AdobeAcrobat XP 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Utility.sys\Spyware - Spybot\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\AdobeAcrobat XP 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\AdobeAcrobat XP 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\AdobeAcrobat XP 6.0\Acrobat\AcroIEFavClient.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\AdobeAcrobat XP 6.0\Acrobat\AcroIEFavClient.dll ()
O4 - HKLM..\Run: [AIRPLUS] C:\Program Files\D-Link\AIRPLUS.exe (D-Link)
O4 - HKLM..\Run: [ATIPTA] C:\WINDOWS\System32\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [avast5] C:\Utility.sys\Spyware - Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE (Vimicro)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [BuffaloTools] C:\Program Files\BUFFALO\BuffaloTools\BuffaloTools.exe (BUFFALO INC.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Utility.sys\Spyware - Comodo\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKCU..\Run: [eFax 4.4] C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe (j2 Global Communications, Inc.)
O4 - HKCU..\Run: [H/PC Connection Agent] C:\Program Files\Microsoft ActiveSync\wcescomm.exe (Microsoft Corporation)
O4 - HKCU..\Run: [i8kfangui] C:\Utility.sys\I8kFanGui\I8kfanGUI.exe (Christian Diefer)
O4 - Startup: C:\Documents and Settings\Carl\Start Menu\Programs\Startup\_drives.lnk = C:\_drives.bat ()
O4 - Startup: C:\Documents and Settings\Carl\Start Menu\Programs\Startup\NetPerSec.lnk = C:\Utility.sys\NetPerSec\NetPerSec.exe (Ziff-Davis Media, Inc.)
O4 - Startup: C:\Documents and Settings\Carl\Start Menu\Programs\Startup\SpinWizard.lnk = C:\Spinwiz\SPINWIZ.EXE ()
O4 - Startup: C:\Documents and Settings\Carl\Start Menu\Programs\Startup\GMER Catchme Real-time Resident Rootkit Scanner.lnk = C:\Utility.sys\Spyware GMER Rootkit\catchme.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Telecom\_Iphone.dir\IM\aim.exe (America Online, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Utility.sys\Spyware - Spybot\SDHelper.dll (Safer Networking Limited)
O12 - Plugin for: .fpx - C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll ()
O12 - Plugin for: .ivr - C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll ()
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} Reg Error: Value error. (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: DirectAnimation Java Classes Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java Reg Error: Value error. (Reg Error: Key error.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\WINDOWS\IslandView2.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\IslandView2.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/05/30 16:16:54 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: VIDC.NTN1 - C:\WINDOWS\System32\NUVision.ax (Zoran Ltd.)
Drivers32: VIDC.PIM1 - C:\WINDOWS\System32\pclepim1.dll (Pinnacle Systems)
Drivers32: VIDC.PIXL - C:\WINDOWS\System32\pclepixl.dll (Pinnacle Systems)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54901231209938944)
========== Files/Folders - Created Within 30 Days ==========
[2010/12/02 15:53:54 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Carl\Desktop\OTL.exe
[2010/12/01 15:54:17 | 000,000,000 | -HSD | C] -- C:\Recycled
[2010/12/01 14:43:15 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/12/01 14:28:08 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/12/01 14:28:08 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/12/01 14:28:08 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/12/01 14:28:08 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/12/01 14:27:46 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010/12/01 14:23:34 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/11/29 20:49:12 | 000,000,000 | ---D | C] -- C:\FOUND.002
[2010/11/19 13:50:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Carl\Application Data\Malwarebytes
[2010/11/19 13:49:48 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/11/19 13:49:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/11/19 13:49:44 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/11/19 07:58:02 | 000,000,000 | ---D | C] -- C:\FOUND.001
[2010/11/18 23:07:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Skype
[2010/11/11 13:30:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Carl\Application Data\BUFFALO
[2010/11/11 13:30:39 | 000,398,712 | R--- | C] (BUFFALO INC.) -- C:\WINDOWS\UN091114.EXE
[2010/11/11 13:30:36 | 000,039,680 | R--- | C] (BUFFALO INC.) -- C:\WINDOWS\System32\drivers\bftpdskc.sys
[2010/11/11 13:30:35 | 000,398,712 | R--- | C] (BUFFALO INC.) -- C:\WINDOWS\UN091111.EXE
[2010/11/11 13:30:35 | 000,010,624 | R--- | C] (BUFFALO INC.) -- C:\WINDOWS\System32\drivers\bftpusbx.sys
[2010/11/11 13:30:32 | 000,398,712 | R--- | C] (BUFFALO INC.) -- C:\WINDOWS\UN091201.EXE
[2010/11/11 13:29:37 | 000,398,712 | R--- | C] (BUFFALO INC.) -- C:\WINDOWS\UN090430.EXE
[2010/11/11 13:29:36 | 000,000,000 | ---D | C] -- C:\Program Files\BUFFALO
[2010/11/05 20:22:54 | 000,000,000 | ---D | C] -- C:\FOUND.000
[2010/11/02 21:09:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[1998/12/09 01:53:54 | 000,186,368 | ---- | C] (Symantec Corp., Peter Norton Computing Group) -- C:\Program Files\Common Files\IRAREG.DLL
[1998/12/09 01:53:54 | 000,099,840 | ---- | C] (Symantec Corp.) -- C:\Program Files\Common Files\IRAABOUT.DLL
[1998/12/09 01:53:54 | 000,070,144 | ---- | C] (Symantec Corp., Peter Norton Computing Group) -- C:\Program Files\Common Files\IRAMDMTR.DLL
[1998/12/09 01:53:54 | 000,048,640 | ---- | C] (Symantec Corp., Peter Norton Computing Group) -- C:\Program Files\Common Files\IRALPTTR.DLL
[1998/12/09 01:53:54 | 000,031,744 | ---- | C] (Symantec Corp., Peter Norton Computing Group) -- C:\Program Files\Common Files\IRAWEBTR.DLL
[1998/12/09 01:53:54 | 000,017,920 | ---- | C] (Symantec Corp.) -- C:\Program Files\Common Files\IRASRIAL.DLL
========== Files - Modified Within 30 Days ==========
[2010/12/02 17:05:14 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/02 16:41:48 | 000,047,011 | ---- | M] () -- C:\WINDOWS\Spinwiz.ar
[2010/12/02 16:41:48 | 000,000,187 | ---- | M] () -- C:\WINDOWS\Spinwiz.ini
[2010/12/02 16:25:28 | 000,000,316 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2010/12/02 16:25:26 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/02 16:24:26 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/12/02 15:53:52 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Carl\Desktop\OTL.exe
[2010/12/02 13:51:20 | 000,002,347 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/12/02 10:49:02 | 000,000,012 | ---- | M] () -- C:\WINDOWS\bthservsdp.dat
[2010/12/01 14:43:26 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2010/12/01 12:47:00 | 003,983,387 | R--- | M] () -- C:\Documents and Settings\Carl\Desktop\ComboFix.exe
[2010/12/01 12:07:08 | 000,080,384 | ---- | M] () -- C:\Documents and Settings\Carl\Desktop\MBRCheck.exe
[2010/11/25 10:21:38 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/11/24 10:11:52 | 000,002,473 | ---- | M] () -- C:\Documents and Settings\Carl\Desktop\Word.lnk
[2010/11/19 13:49:54 | 000,000,556 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/19 13:32:12 | 000,002,471 | ---- | M] () -- C:\Documents and Settings\Carl\Desktop\Excel.lnk
[2010/11/18 11:14:22 | 000,002,622 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/11/11 15:16:14 | 000,001,379 | ---- | M] () -- C:\Documents and Settings\Carl\Desktop\Windows Explorer.lnk
[2010/11/10 21:23:56 | 000,000,550 | ---- | M] () -- C:\Documents and Settings\Carl\Desktop\Mozilla Thunderbird.lnk
[2010/11/08 20:24:00 | 001,012,064 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/11/08 01:20:24 | 000,089,088 | ---- | M] () -- C:\WINDOWS\MBR.exe
[2010/11/03 05:43:26 | 000,000,876 | ---- | M] () -- C:\WINDOWS\wininit.ini
========== Files Created - No Company Name ==========
[2010/12/01 14:43:23 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/12/01 14:43:18 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2010/12/01 14:28:08 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/12/01 14:28:08 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/12/01 14:28:08 | 000,089,088 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/12/01 14:28:08 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/12/01 14:28:08 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/12/01 12:46:16 | 003,983,387 | R--- | C] () -- C:\Documents and Settings\Carl\Desktop\ComboFix.exe
[2010/12/01 12:07:47 | 000,080,384 | ---- | C] () -- C:\Documents and Settings\Carl\Desktop\MBRCheck.exe
[2010/11/29 14:04:39 | 000,000,187 | ---- | C] () -- C:\WINDOWS\Spinwiz.ini
[2010/11/19 13:49:52 | 000,000,556 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/18 23:09:05 | 000,002,347 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/11/11 13:30:39 | 000,012,448 | R--- | C] () -- C:\WINDOWS\UN091114.INI
[2010/11/11 13:30:35 | 000,030,592 | R--- | C] () -- C:\WINDOWS\UN091111.INI
[2010/11/11 13:30:32 | 000,012,167 | R--- | C] () -- C:\WINDOWS\UN091201.INI
[2010/11/11 13:29:37 | 000,009,793 | R--- | C] () -- C:\WINDOWS\UN090430.INI
[2008/12/01 14:54:00 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2008/12/01 14:51:23 | 000,000,044 | ---- | C] () -- C:\WINDOWS\EPSNX300.ini
[2008/11/27 23:55:10 | 000,000,297 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2008/11/27 23:55:09 | 000,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2008/04/07 17:09:42 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/12/16 13:38:44 | 000,008,192 | ---- | C] () -- C:\Documents and Settings\Carl\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/10/28 19:56:48 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Carl\Application Data\$_hpcst$.hpc
[2007/08/18 21:08:06 | 000,000,049 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2006/12/17 20:32:24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2006/08/19 12:57:37 | 000,000,029 | ---- | C] () -- C:\WINDOWS\qbwcd.ini
[2006/08/19 12:47:38 | 000,001,385 | ---- | C] () -- C:\WINDOWS\QfnOnl.ini
[2006/08/19 12:47:29 | 000,000,362 | ---- | C] () -- C:\WINDOWS\QDQICK.INI
[2006/08/19 12:47:29 | 000,000,038 | ---- | C] () -- C:\WINDOWS\ACCWIZ.INI
[2006/08/19 12:47:29 | 000,000,021 | ---- | C] () -- C:\WINDOWS\QFNOA.INI
[2006/08/06 14:42:07 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\yayxx.dll
[2006/07/26 19:21:33 | 000,000,020 | ---- | C] () -- C:\WINDOWS\DOSAPP.INI
[2006/07/09 17:32:14 | 000,000,135 | ---- | C] () -- C:\WINDOWS\EPSON CX5200 Installer.ini
[2006/03/22 16:37:33 | 000,233,606 | ---- | C] () -- C:\WINDOWS\System32\jswsup.dll
[2006/01/18 02:44:02 | 000,045,699 | ---- | C] () -- C:\WINDOWS\unvpeye.ini
[2005/12/05 16:35:40 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/11/18 22:06:56 | 000,000,182 | ---- | C] () -- C:\WINDOWS\dgnsetup.ini
[2005/11/17 21:26:29 | 000,028,747 | ---- | C] () -- C:\WINDOWS\System32\KMemoryMMX.dll
[2005/11/17 21:26:29 | 000,024,653 | ---- | C] () -- C:\WINDOWS\System32\KMemoryPIII.dll
[2005/11/17 21:26:29 | 000,024,632 | ---- | C] () -- C:\WINDOWS\System32\KMemory.dll
[2005/11/17 21:26:29 | 000,020,546 | ---- | C] () -- C:\WINDOWS\System32\KMemoryC.dll
[2005/11/17 21:25:53 | 000,000,002 | ---- | C] () -- C:\WINDOWS\PhotoSuite.ini
[2005/11/17 21:25:47 | 000,458,752 | ---- | C] () -- C:\WINDOWS\System32\Fpl.dll
[2005/11/17 21:25:47 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\EnrouteStitch.dll
[2005/11/17 21:25:46 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\CPUINF32.DLL
[2005/11/17 21:25:45 | 000,332,800 | ---- | C] () -- C:\WINDOWS\System32\FPXLIB.DLL
[2005/11/17 21:25:45 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\JPEGLIB.DLL
[2005/11/17 20:42:59 | 000,003,565 | ---- | C] () -- C:\WINDOWS\imgfolio.ini
[2005/11/17 20:22:56 | 000,000,290 | ---- | C] () -- C:\WINDOWS\ULEAD32.INI
[2005/08/29 23:51:06 | 000,003,812 | ---- | C] () -- C:\WINDOWS\COOL.INI
[2005/08/20 16:41:10 | 000,003,319 | ---- | C] () -- C:\WINDOWS\WPR.INI
[2005/07/29 16:21:32 | 000,011,988 | ---- | C] () -- C:\WINDOWS\System32\drivers\VBTEnum.sys
[2005/07/23 20:08:45 | 000,000,130 | ---- | C] () -- C:\Documents and Settings\Carl\Local Settings\Application Data\fusioncache.dat
[2005/07/22 23:54:44 | 000,000,636 | ---- | C] () -- C:\WINDOWS\tlknw80.ini
[2005/07/19 20:58:46 | 000,008,179 | ---- | C] () -- C:\WINDOWS\lviewp.ini
[2005/07/17 19:17:53 | 000,000,876 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/07/17 15:04:35 | 000,000,187 | ---- | C] () -- C:\WINDOWS\Spinwiz.bkk.ini
[2005/07/17 14:14:49 | 000,000,022 | ---- | C] () -- C:\WINDOWS\WS_FTP.INI
[2005/06/20 21:55:14 | 000,000,187 | ---- | C] () -- C:\WINDOWS\CoverDes.INI
[2005/06/04 20:13:29 | 000,000,029 | ---- | C] () -- C:\WINDOWS\DEBUGSM.INI
[2005/06/04 19:16:48 | 000,000,021 | ---- | C] () -- C:\WINDOWS\PI_setup.ini
[2005/06/04 19:06:12 | 000,000,204 | ---- | C] () -- C:\WINDOWS\EPSON RX500 Installer.ini
[2005/05/30 23:49:37 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/05/30 17:16:04 | 000,061,616 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinrvxx.sys
[2005/05/30 17:16:04 | 000,058,704 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinbtxx.sys
[2005/05/30 17:16:04 | 000,032,672 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinraxx.sys
[2005/05/30 17:16:04 | 000,027,360 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinxbxx.sys
[2005/05/30 17:16:04 | 000,024,832 | ---- | C] () -- C:\WINDOWS\System32\drivers\atintuxx.sys
[2005/05/30 17:16:04 | 000,023,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\atinsnxx.sys
[2005/05/30 15:50:33 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004/12/16 16:32:54 | 000,013,304 | ---- | C] () -- C:\WINDOWS\System32\drivers\BTNetFilter.sys
[2001/06/24 17:32:44 | 000,172,032 | ---- | C] () -- C:\WINDOWS\japi2.dll
[2000/07/28 18:48:12 | 000,102,400 | ---- | C] () -- C:\WINDOWS\japi.dll
[1999/01/22 17:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
[1998/01/12 07:00:00 | 000,040,448 | ---- | C] () -- C:\WINDOWS\System32\REGOBJ.DLL
[1996/04/03 15:33:26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2005/05/30 23:52:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBT
[2005/07/17 22:35:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2005/07/23 21:53:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2006/06/16 19:11:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\j2 Global
[2006/08/19 11:41:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
[2008/04/11 12:43:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Bluetooth
[2008/12/01 14:53:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EPSON
[2008/12/01 14:57:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\UDL
[2009/08/18 23:07:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Agnitum
[2010/04/19 13:24:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.4 Output
[2010/08/18 05:17:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/28 12:51:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2005/06/04 19:32:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Leadertech
[2005/07/05 21:36:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\EPSON
[2008/09/24 12:04:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\.purple
[2005/07/17 22:36:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Aim
[2005/07/23 20:08:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\IsolatedStorage
[2005/07/23 22:02:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\ScanSoft
[2005/08/20 23:22:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Jasc
[2006/01/19 00:49:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Systweak
[2006/06/16 19:12:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\j2
[2006/07/02 13:14:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\eFax Messenger
[2010/04/19 13:34:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\j2 Global
[2008/08/07 15:54:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\NwDocx
[2008/09/24 12:06:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\gtk-2.0
[2008/09/24 15:59:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Thunderbird
[2009/01/13 20:33:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\GlarySoft
[2009/01/23 11:47:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\Pamela
[2010/11/11 13:30:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Carl\Application Data\BUFFALO
[2010/12/02 16:25:28 | 000,000,316 | ---- | M] () -- C:\WINDOWS\Tasks\GlaryInitialize.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/12/02 16:24:16 | 000,101,146 | ---- | M] () -- C:\BOOTEX.LOG
[2006/01/28 23:15:18 | 000,013,030 | ---- | M] () -- C:\PDOXUSRS.NET
[2005/11/17 21:22:24 | 000,014,147 | ---- | M] () -- C:\PVOEM_debug.txt
[2007/01/29 22:09:02 | 000,000,000 | ---- | M] () -- C:\HPSW.CKI
[2010/11/29 11:48:52 | 000,043,725 | ---- | M] () -- C:\winzip.log
[2005/05/30 17:05:32 | 000,250,032 | RHS- | M] () -- C:\ntldr
[2005/05/30 17:05:32 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2010/12/01 14:43:26 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2005/05/30 16:16:54 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2005/05/30 16:16:54 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2005/05/30 16:16:54 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2005/05/30 16:16:54 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2006/11/26 21:21:40 | 000,000,075 | ---- | M] () -- C:\_drives.bat
[2006/01/16 16:39:36 | 000,000,611 | ---- | M] () -- C:\DeviceManageHiddenDevices.bat
[2007/02/09 00:42:28 | 000,024,064 | ---- | M] () -- C:\fat32format.exe
[2008/01/12 21:57:36 | 000,031,562 | ---- | M] () -- C:\ASLog.txt
[2009/06/25 20:13:44 | 000,000,000 | ---- | M] () -- C:\plx_proxy.log
[2009/07/26 19:02:34 | 000,000,504 | ---- | M] () -- C:\functionalLog.txt
[2005/07/05 21:30:54 | 000,000,094 | ---- | M] () -- C:\twacker.org.log
[2010/12/02 16:24:18 | 402,653,184 | -HS- | M] () -- C:\pagefile.sys
[2010/11/19 18:26:48 | 000,001,605 | ---- | M] () -- C:\rkill.log
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () -- C:\cmldr
[2006/08/19 11:42:54 | 000,000,211 | ---- | M] () -- C:\Boot.bak