OTL.txt
OTL logfile created on: 3/23/2012 1:02:42 AM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Kelli\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.49 Gb Total Physical Memory | 2.12 Gb Available Physical Memory | 60.62% Memory free
7.16 Gb Paging File | 6.05 Gb Available in Paging File | 84.54% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220.58 Gb Total Space | 58.87 Gb Free Space | 26.69% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 5.42 Gb Free Space | 55.54% Space Free | Partition Type: NTFS
Computer Name: KRIS-PC | User Name: Kelli | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/03/23 01:00:45 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Kelli\Desktop\OTL.exe
PRC - [2011/06/15 15:16:48 | 000,997,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2011/06/01 08:44:55 | 002,120,568 | ---- | M] (TeamViewer GmbH) -- c:\Program Files\TeamViewer\Version6\TeamViewer_Desktop.exe
PRC - [2011/06/01 08:44:54 | 008,003,448 | ---- | M] (TeamViewer GmbH) -- c:\Program Files\TeamViewer\Version6\TeamViewer.exe
PRC - [2011/06/01 08:44:54 | 002,337,144 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe
PRC - [2011/06/01 08:16:33 | 000,108,408 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version6\tv_w32.exe
PRC - [2011/05/06 13:07:18 | 000,460,144 | ---- | M] () -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
PRC - [2011/05/06 12:58:52 | 001,085,440 | ---- | M] () -- C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe
PRC - [2011/04/27 15:39:26 | 000,208,944 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
PRC - [2011/04/27 15:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
PRC - [2008/10/29 02:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/08/14 00:04:44 | 000,201,968 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/04/28 17:56:28 | 000,161,048 | ---- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2008/02/22 18:01:38 | 001,193,240 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2007/11/12 07:07:20 | 000,102,400 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\stacsv.exe
PRC - [2007/11/12 07:07:16 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEstSrv.exe
PRC - [2007/03/21 14:00:04 | 000,355,096 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007/01/04 17:38:08 | 000,024,652 | -H-- | M] (Viewpoint Corporation) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe
========== Modules (No Company Name) ==========
MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Users\Kelli\AppData\Local\Temp\002907~1.EXE -- (0029071332293059mcinstcleanup) McAfee Application Installer Cleanup (0029071332293059)
SRV - [2011/06/01 08:44:54 | 002,337,144 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2011/05/06 13:07:18 | 000,460,144 | ---- | M] () [Auto | Running] -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe -- (FlipShare Service)
SRV - [2011/05/06 12:58:52 | 001,085,440 | ---- | M] () [Auto | Running] -- C:\Program Files\Flip Video\FlipShareServer\FlipShareServer.exe -- (FlipShareServer)
SRV - [2011/04/27 15:39:26 | 000,208,944 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV - [2011/04/27 15:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2008/08/14 00:04:44 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter)
SRV - [2008/04/28 17:56:28 | 000,161,048 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV - [2008/01/20 22:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/11/12 07:07:20 | 000,102,400 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\stacsv.exe -- (STacSV)
SRV - [2007/11/12 07:07:16 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEstSrv.exe -- (AESTFilters)
SRV - [2007/03/21 14:00:04 | 000,355,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
SRV - [2007/01/04 17:38:08 | 000,024,652 | -H-- | M] (Viewpoint Corporation) [Auto | Running] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
SRV - [2006/10/31 10:32:09 | 002,541,248 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE -- (LiveUpdate)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\ComboFix\mbr.sys -- (mbr)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\Users\Kelli\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - [2011/04/27 15:25:24 | 000,065,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2011/04/18 13:18:50 | 000,043,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MpNWMon.sys -- (MpNWMon)
DRV - [2008/05/04 05:25:24 | 000,164,400 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2008/03/06 03:58:44 | 000,111,616 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService) Intel(R)
DRV - [2008/03/04 01:05:34 | 000,007,424 | ---- | M] (EyePower Games Pte. Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM02Vfx.sys -- (OEM02Vfx)
DRV - [2008/03/04 01:05:18 | 000,235,648 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM02Dev.sys -- (OEM02Dev)
DRV - [2008/01/20 22:23:25 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express) Intel(R)
DRV - [2007/11/12 07:07:28 | 000,330,240 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2007/09/06 12:35:16 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/09/06 12:35:14 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/09/06 12:35:12 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2007/08/13 05:44:26 | 002,226,688 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32) Intel(R)
DRV - [2006/11/02 03:36:43 | 002,028,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2006/08/04 20:39:10 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}: "URL" = http://slirsredirect.search.aol.com/redirector/sredir?sredir=2706&query={searchTerms}&invocationType=tb50-ie-aim-chromesbox-en-us&tb_uuid=20100414232719829&tb_oid=01-05-2009&tb_mrud=03-11-2010
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7DKUS
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2274276225-3462577313-1908128153-1002\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-21-2274276225-3462577313-1908128153-1002\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2274276225-3462577313-1908128153-1002\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKU\S-1-5-21-2274276225-3462577313-1908128153-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "WOT Safe Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7550
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/20 21:51:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/03/20 21:51:57 | 000,000,000 | ---D | M]
[2012/03/20 21:24:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kelli\AppData\Roaming\Mozilla\Extensions
[2012/03/20 21:54:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kelli\AppData\Roaming\Mozilla\Firefox\Profiles\l79wd44r.default\extensions
[2012/03/20 21:54:14 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Kelli\AppData\Roaming\Mozilla\Firefox\Profiles\l79wd44r.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2012/03/20 21:54:20 | 000,002,112 | ---- | M] () -- C:\Users\Kelli\AppData\Roaming\Mozilla\Firefox\Profiles\l79wd44r.default\searchplugins\wot-safe-search.xml
[2012/03/20 21:51:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2008/08/09 11:43:52 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/06/19 23:09:16 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/03/13 00:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/04/16 13:07:12 | 000,180,293 | -H-- | M] () -- C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2012/03/13 00:38:32 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/03/20 18:46:05 | 000,002,024 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2012/03/13 00:38:32 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/03/23 00:47:47 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKU\S-1-5-21-2274276225-3462577313-1908128153-1002\..\Toolbar\WebBrowser: (AIM Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O3 - HKU\S-1-5-21-2274276225-3462577313-1908128153-1002\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Rollbackrx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-2274276225-3462577313-1908128153-1002\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2274276225-3462577313-1908128153-1002\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-2274276225-3462577313-1908128153-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {4D2D3A17-9B46-483C-A5F4-1DC471080009}
https://wmtss1.wcsu.edu/auth/taweb.cab (Cisco NAC Web Agent Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809}
http://www.cvsphoto.com/upload/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab (Photo Upload Plugin Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 167.206.251.129 167.206.251.130
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9F7136FC-BD10-40C5-BB3A-A09C78481805}: DhcpNameServer = 167.206.251.129 167.206.251.130
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.3IV2 - C:\Windows\System32\3ivxVfWCodec.dll (3ivx Technologies Pty. Ltd.)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/03/23 01:00:33 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Users\Kelli\Desktop\OTL.exe
[2012/03/23 00:50:30 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/03/23 00:50:25 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\temp
[2012/03/23 00:33:47 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/03/23 00:33:47 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/03/23 00:33:47 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/03/23 00:33:39 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/03/23 00:33:38 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/03/23 00:33:33 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/03/23 00:31:08 | 004,443,082 | R--- | C] (Swearware) -- C:\Users\Kelli\Desktop\ComboFix.exe
[2012/03/22 23:13:56 | 001,932,256 | ---- | C] (Symantec Corporation) -- C:\Users\Kelli\Desktop\FixTDSS.exe
[2012/03/22 22:42:55 | 000,000,000 | ---D | C] -- C:\Users\Kelli\Desktop\tdsskiller
[2012/03/22 22:27:01 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\Apple
[2012/03/22 22:16:44 | 000,000,000 | ---D | C] -- C:\Users\Kelli\Desktop\bootkit_remover
[2012/03/22 21:56:05 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Kelli\Desktop\aswMBR.exe
[2012/03/22 09:59:32 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Kelli\Desktop\dds.scr
[2012/03/22 09:45:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/03/22 09:45:46 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/03/22 09:45:45 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/03/22 08:30:32 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/03/21 01:03:37 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Roaming\SUPERAntiSpyware.com
[2012/03/21 01:02:42 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2012/03/20 22:04:16 | 000,000,000 | ---D | C] -- C:\Program Files\WOT
[2012/03/20 21:49:40 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\Adobe
[2012/03/20 21:24:33 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Roaming\Mozilla
[2012/03/20 21:24:33 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\Mozilla
[2012/03/20 21:21:35 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\~Disabled
[2012/03/20 21:14:27 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\Stardock_Corporation
[2012/03/20 21:14:11 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\AIM Toolbar
[2012/03/20 21:12:14 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Roaming\Intel
[2012/03/20 21:08:47 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\KodakGallery
[2012/03/20 21:06:37 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Roaming\Apple Computer
[2012/03/20 21:06:24 | 000,000,000 | ---D | C] -- C:\Users\Kelli\Documents\My Google Gadgets
[2012/03/20 21:06:23 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\Apple Computer
[2012/03/20 21:06:13 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\MediaDirect
[2012/03/20 21:06:12 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\Google
[2012/03/20 21:05:52 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\SupportSoft
[2012/03/20 21:05:50 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\Symantec
[2012/03/20 21:05:19 | 000,000,000 | R--D | C] -- C:\Users\Kelli\Searches
[2012/03/20 21:05:19 | 000,000,000 | R--D | C] -- C:\Users\Kelli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/03/20 21:05:05 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Roaming\Identities
[2012/03/20 21:05:01 | 000,000,000 | R--D | C] -- C:\Users\Kelli\Contacts
[2012/03/20 21:05:01 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Roaming\Dell
[2012/03/20 21:04:18 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\VirtualStore
[2012/03/20 19:38:44 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Roaming\Macromedia
[2012/03/20 19:36:31 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Roaming\Malwarebytes
[2012/03/20 19:36:06 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Roaming\Adobe
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\AppData\Local\Temporary Internet Files
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\Templates
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\Start Menu
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\SendTo
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\Recent
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\PrintHood
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\NetHood
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\Documents\My Videos
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\Documents\My Pictures
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\Documents\My Music
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\My Documents
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\Local Settings
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\AppData\Local\History
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\Cookies
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\Application Data
[2012/03/20 19:35:47 | 000,000,000 | -HSD | C] -- C:\Users\Kelli\AppData\Local\Application Data
[2012/03/20 19:35:46 | 000,000,000 | --SD | C] -- C:\Users\Kelli\AppData\Roaming\Microsoft
[2012/03/20 19:35:46 | 000,000,000 | R--D | C] -- C:\Users\Kelli\Videos
[2012/03/20 19:35:46 | 000,000,000 | R--D | C] -- C:\Users\Kelli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/03/20 19:35:46 | 000,000,000 | R--D | C] -- C:\Users\Kelli\Saved Games
[2012/03/20 19:35:46 | 000,000,000 | R--D | C] -- C:\Users\Kelli\Pictures
[2012/03/20 19:35:46 | 000,000,000 | R--D | C] -- C:\Users\Kelli\Music
[2012/03/20 19:35:46 | 000,000,000 | R--D | C] -- C:\Users\Kelli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/03/20 19:35:46 | 000,000,000 | R--D | C] -- C:\Users\Kelli\Links
[2012/03/20 19:35:46 | 000,000,000 | R--D | C] -- C:\Users\Kelli\Favorites
[2012/03/20 19:35:46 | 000,000,000 | R--D | C] -- C:\Users\Kelli\Downloads
[2012/03/20 19:35:46 | 000,000,000 | R--D | C] -- C:\Users\Kelli\Documents
[2012/03/20 19:35:46 | 000,000,000 | R--D | C] -- C:\Users\Kelli\Desktop
[2012/03/20 19:35:46 | 000,000,000 | R--D | C] -- C:\Users\Kelli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/03/20 19:35:46 | 000,000,000 | -H-D | C] -- C:\Users\Kelli\AppData
[2012/03/20 19:35:46 | 000,000,000 | ---D | C] -- C:\Users\Kelli\Roaming
[2012/03/20 19:35:46 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\Microsoft Help
[2012/03/20 19:35:46 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Local\Microsoft
[2012/03/20 19:35:46 | 000,000,000 | ---D | C] -- C:\Users\Kelli\AppData\Roaming\Media Center Programs
[2012/03/20 19:30:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/03/20 19:30:13 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012/03/20 19:02:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/03/20 18:25:39 | 000,000,000 | ---D | C] -- C:\usr
[2012/03/20 17:54:29 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer
========== Files - Modified Within 30 Days ==========
[2012/03/23 01:04:00 | 000,000,390 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{8664DD1A-9AE7-4396-976B-16D3119F0393}.job
[2012/03/23 01:00:45 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Kelli\Desktop\OTL.exe
[2012/03/23 00:47:47 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/03/23 00:36:37 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/23 00:31:08 | 004,443,082 | R--- | M] (Swearware) -- C:\Users\Kelli\Desktop\ComboFix.exe
[2012/03/23 00:14:47 | 000,606,602 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/03/23 00:14:47 | 000,105,170 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/03/23 00:08:06 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/23 00:07:15 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/23 00:07:15 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/23 00:07:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/03/22 23:14:00 | 001,932,256 | ---- | M] (Symantec Corporation) -- C:\Users\Kelli\Desktop\FixTDSS.exe
[2012/03/22 22:45:21 | 000,006,648 | ---- | M] () -- C:\Users\Kelli\AppData\Local\d3d9caps.dat
[2012/03/22 22:42:47 | 002,047,211 | ---- | M] () -- C:\Users\Kelli\Desktop\tdsskiller.zip
[2012/03/22 22:24:40 | 000,304,845 | ---- | M] () -- C:\Users\Kelli\Desktop\ListParts.exe
[2012/03/22 22:16:32 | 000,044,607 | ---- | M] () -- C:\Users\Kelli\Desktop\bootkit_remover.zip
[2012/03/22 21:53:38 | 297,433,374 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/03/22 21:50:09 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Kelli\Desktop\aswMBR.exe
[2012/03/22 09:59:41 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Kelli\Desktop\dds.scr
[2012/03/22 09:57:03 | 000,302,592 | ---- | M] () -- C:\Users\Kelli\Desktop\ujdq415g.exe
[2012/03/22 09:45:58 | 000,000,908 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/22 08:30:51 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/03/21 00:38:25 | 000,382,264 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/03/20 22:02:52 | 000,000,104 | ---- | M] () -- C:\Users\Kelli\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet - Shortcut.lnk
[2012/03/20 22:02:27 | 000,000,951 | ---- | M] () -- C:\Users\Kelli\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
[2012/03/11 03:00:06 | 000,154,624 | RH-- | M] () -- C:\Users\Public\Documents\ESBK.mbb
[2012/03/11 03:00:06 | 000,106,496 | RH-- | M] () -- C:\Users\Public\Documents\ESBK.mb
========== Files Created - No Company Name ==========
[2012/03/23 00:33:47 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/03/23 00:33:47 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/03/23 00:33:47 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/03/23 00:33:47 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/03/23 00:33:47 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/03/22 22:42:38 | 002,047,211 | ---- | C] () -- C:\Users\Kelli\Desktop\tdsskiller.zip
[2012/03/22 22:24:27 | 000,304,845 | ---- | C] () -- C:\Users\Kelli\Desktop\ListParts.exe
[2012/03/22 22:16:29 | 000,044,607 | ---- | C] () -- C:\Users\Kelli\Desktop\bootkit_remover.zip
[2012/03/22 21:53:11 | 297,433,374 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/03/22 09:56:41 | 000,302,592 | ---- | C] () -- C:\Users\Kelli\Desktop\ujdq415g.exe
[2012/03/22 09:45:58 | 000,000,908 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/22 08:30:37 | 000,001,810 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/03/20 22:16:41 | 000,006,648 | ---- | C] () -- C:\Users\Kelli\AppData\Local\d3d9caps.dat
[2012/03/20 22:10:13 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
[2012/03/20 22:02:52 | 000,000,104 | ---- | C] () -- C:\Users\Kelli\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet - Shortcut.lnk
[2012/03/20 22:02:27 | 000,000,951 | ---- | C] () -- C:\Users\Kelli\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Explorer.lnk
[2012/03/20 21:51:59 | 000,000,860 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/03/20 21:05:29 | 000,000,951 | ---- | C] () -- C:\Users\Kelli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/03/20 21:05:17 | 000,000,946 | ---- | C] () -- C:\Users\Kelli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2012/03/20 21:05:01 | 000,000,917 | ---- | C] () -- C:\Users\Kelli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
[2012/03/20 19:35:46 | 000,000,258 | ---- | C] () -- C:\Users\Kelli\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/03/20 19:35:46 | 000,000,240 | ---- | C] () -- C:\Users\Kelli\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/03/20 17:54:38 | 000,000,969 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 6.lnk
[2010/09/07 22:25:57 | 000,815,104 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2010/09/07 22:25:56 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010/07/22 22:25:24 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
========== LOP Check ==========
[2012/03/23 00:06:11 | 000,032,542 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/03/23 01:04:00 | 000,000,390 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{8664DD1A-9AE7-4396-976B-16D3119F0393}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 17:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2008/01/20 22:24:42 | 000,333,203 | RHS- | M] () -- C:\bootmgr
[2012/03/23 00:50:23 | 000,007,876 | ---- | M] () -- C:\ComboFix.txt
[2006/09/18 17:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2008/07/30 17:07:28 | 000,003,823 | RH-- | M] () -- C:\dell.sdr
[2011/02/16 09:37:45 | 000,001,105 | -H-- | M] () -- C:\IPH.PH
[2012/03/23 00:06:58 | 4061,261,824 | -HS- | M] () -- C:\pagefile.sys
[2008/07/30 14:46:21 | 000,000,071 | ---- | M] () -- C:\SystemInfo.ini
[2012/03/23 00:29:35 | 000,117,904 | ---- | M] () -- C:\TDSSKiller.2.7.22.0_23.03.2012_00.09.33_log.txt
[2008/10/26 15:15:31 | 000,000,594 | ---- | M] () -- C:\updatedatfix.log
< %systemroot%\Fonts\*.com >
[2006/11/02 08:37:12 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 08:37:12 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 08:37:12 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 08:37:12 | 000,030,808 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 17:37:34 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/12/17 18:05:32 | 000,278,016 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2008/01/20 22:23:14 | 000,089,600 | ---- | M] (Hewlett-Packard Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 08:35:48 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 19:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 22:43:21 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 23:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 23:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 23:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 06:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 06:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/03/20 22:02:27 | 000,000,281 | -HS- | M] () -- C:\Users\Kelli\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/03/22 21:50:09 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Kelli\Desktop\aswMBR.exe
[2012/03/23 00:31:08 | 004,443,082 | R--- | M] (Swearware) -- C:\Users\Kelli\Desktop\ComboFix.exe
[2012/03/22 23:14:00 | 001,932,256 | ---- | M] (Symantec Corporation) -- C:\Users\Kelli\Desktop\FixTDSS.exe
[2012/03/22 22:24:40 | 000,304,845 | ---- | M] () -- C:\Users\Kelli\Desktop\ListParts.exe
[2012/03/23 01:00:45 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Kelli\Desktop\OTL.exe
[2012/03/22 09:57:03 | 000,302,592 | ---- | M] () -- C:\Users\Kelli\Desktop\ujdq415g.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\tasks\*.* >
[2012/03/23 00:08:06 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/03/23 00:36:37 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/03/23 00:07:07 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2012/03/23 00:06:11 | 000,032,542 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
[2012/03/23 01:09:00 | 000,000,390 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{8664DD1A-9AE7-4396-976B-16D3119F0393}.job
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2012/03/20 21:05:19 | 000,000,402 | -HS- | M] () -- C:\Users\Kelli\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2009/12/30 18:12:35 | 000,002,364 | ---- | M] () -- C:\ProgramData\hpzinstall.log
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
< %SYSTEMROOT%\Installer\*.exe >
[2007/08/13 05:05:24 | 000,600,328 | ---- | M] (Intel Corporation) -- C:\Windows\Installer\iProInst.exe
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\ Auto Update\Results\Install|LastSuccessTime /rs >
< >
< End of report >